CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,252
Total CVEs
21
Critical
303
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,252)

CVE-2025-38135
5.5

A NULL pointer dereference vulnerability in the Linux kernel's serial driver could cause kernel panic or system crash when devm_ioremap() fails. This ...

Jul 3, 2025
CVE-2025-38122
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's gve driver for Google Virtual Ethernet. When the gve_alloc_pending_p...

Jul 3, 2025
CVE-2025-38095
5.5

A memory barrier ordering issue in the Linux kernel's dma-buf subsystem can lead to a NULL pointer dereference when memory updates are reordered. This...

Jul 3, 2025
CVE-2025-38092
5.5

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's ksmbd module, which handles SMB file sharing. If exploited, it could...

Jul 2, 2025
CVE-2025-38089
5.5

A NULL pointer dereference vulnerability in the Linux kernel's sunrpc component allows remote attackers to crash the kernel or potentially cause memor...

Jun 30, 2025
CVE-2022-50206
5.5

This CVE describes a race condition vulnerability in the Linux kernel's ARM64 instruction emulation sysctl handlers. When multiple processes concurren...

Jun 18, 2025
CVE-2022-50181
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's virtio-gpu driver. If exploited, it could cause a kernel panic leadi...

Jun 18, 2025
CVE-2022-50144
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's SoundWire subsystem that can cause kernel oopses (crashes) when unbi...

Jun 18, 2025
CVE-2022-50133
5.5

A NULL pointer dereference vulnerability in the Linux kernel's xHCI USB host controller driver causes a kernel panic during system reboot when xhci->s...

Jun 18, 2025
CVE-2022-50135
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's RDMA over Converged Ethernet (RoCE) implementation. When error handl...

Jun 18, 2025
CVE-2022-50078
5.5

A vulnerability in the Linux kernel's tracing subsystem allows event probes (eprobes) to incorrectly access register variables like $stack or %reg whe...

Jun 18, 2025
CVE-2022-50068
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's TTM (Translation Table Maps) memory management subsystem. When a buf...

Jun 18, 2025
CVE-2022-50054
5.5

A NULL pointer dereference vulnerability in the Linux kernel's iavf driver allows local users to crash the system via a kernel panic. This affects sys...

Jun 18, 2025
CVE-2022-50056
5.5

A null pointer dereference vulnerability in the Linux kernel's NTFS3 filesystem driver allows local attackers to crash the system or potentially escal...

Jun 18, 2025
CVE-2022-50058
5.5

A NULL pointer dereference vulnerability in the Linux kernel's vdpa_sim_blk driver causes kernel panic when creating virtual block devices. This affec...

Jun 18, 2025
CVE-2022-50016
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem for Intel Cannon Lake (CNL) platforms allows a mali...

Jun 18, 2025
CVE-2022-50003
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Intel ice driver when using XDP sockets (XSK) with unbalanced queue ...

Jun 18, 2025
CVE-2022-50009
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's F2FS filesystem driver. When atomic write operations are performed o...

Jun 18, 2025
CVE-2022-49989
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Xen privcmd driver could cause kernel crashes or memory corruption when handling certai...

Jun 18, 2025
CVE-2022-49977
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ftrace subsystem allows local attackers to cause a kernel panic (denial of service) whe...

Jun 18, 2025
CVE-2022-49984
5.5

A NULL pointer dereference vulnerability in the Linux kernel's HID Steam driver allows malicious USB devices to crash the kernel by not submitting req...

Jun 18, 2025
CVE-2022-49973
5.5

A NULL pointer dereference vulnerability in the Linux kernel's sk_msg_recvmsg() function can cause kernel crashes when handling socket redirection via...

Jun 18, 2025
CVE-2022-49960
5.5

A null pointer dereference vulnerability in the Linux kernel's Intel i915 graphics driver causes kernel panics during system boot on affected devices....

Jun 18, 2025
CVE-2022-49942
5.5

This vulnerability in the Linux kernel's WiFi subsystem causes a kernel warning/panic when attempting to send channel switch announcements in IBSS (ad...

Jun 18, 2025
CVE-2022-49944
5.5

A NULL pointer dereference vulnerability in the Linux kernel's USB Type-C UCSI subsystem allows local attackers to cause a kernel panic (system crash)...

Jun 18, 2025
CVE-2022-49947
5.5

This vulnerability is a null pointer dereference in the Linux kernel's binder driver that can cause kernel crashes or denial of service. It affects An...

Jun 18, 2025
CVE-2025-38070
5.5

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's sma1307 audio codec driver. If exploited, it could cause kernel cras...

Jun 18, 2025
CVE-2025-38055
5.5

A NULL pointer dereference vulnerability in the Linux kernel's perf/x86/intel subsystem causes a kernel panic (segfault) when using PEBS-via-PT with s...

Jun 18, 2025
CVE-2025-38059
5.5

A NULL pointer dereference vulnerability in the Linux kernel's btrfs filesystem allows local attackers to crash the system when performing read-only s...

Jun 18, 2025
CVE-2025-38050
5.5

A race condition in the Linux kernel's hugetlb subsystem can cause a NULL pointer dereference when replacing free huge pages, leading to kernel panic ...

Jun 18, 2025
CVE-2025-38053
5.5

A NULL pointer dereference vulnerability in the Linux kernel's idpf driver allows local attackers to cause a kernel panic (denial of service) by trigg...

Jun 18, 2025
CVE-2025-38035
5.5

A NULL pointer dereference vulnerability in the Linux kernel's NVMe over TCP (nvmet-tcp) subsystem can cause kernel crashes when TCP connections aren'...

Jun 18, 2025
CVE-2025-38021
5.5

A null pointer dereference vulnerability in the Linux kernel's AMD display driver could cause kernel crashes or system instability. This affects Linux...

Jun 18, 2025
CVE-2025-38007
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's HID uclogic driver when memory allocation fails. This could cause kernel crashes...

Jun 18, 2025
CVE-2025-30321
5.5

Adobe InDesign has a NULL pointer dereference vulnerability that allows attackers to cause application crashes via malicious files. Users must open a ...

Jun 10, 2025
CVE-2025-20676
5.5

This vulnerability in MediaTek's WLAN STA driver allows local attackers with user privileges to trigger a system crash through an uncaught exception, ...

Jun 2, 2025
CVE-2025-37994
5.5

A NULL pointer dereference vulnerability in the Linux kernel's UCSI DisplayPort driver could cause kernel crashes or system instability when USB-C dev...

May 29, 2025
CVE-2025-37992
5.5

A NULL pointer dereference vulnerability in the Linux kernel's network scheduler (net_sched) occurs when reducing a qdisc's limit via the ->change() o...

May 26, 2025
CVE-2025-37971
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's bcm2835-camera driver. When exploited, it causes a kernel panic (sys...

May 20, 2025
CVE-2025-37945
5.5

A Linux kernel vulnerability in the network PHY subsystem allows improper handling of PHY state machine during suspend/resume operations when using ph...

May 20, 2025
CVE-2025-37938
5.5

A vulnerability in the Linux kernel's tracing subsystem allows reading freed memory when trace events use specific format specifiers. This could lead ...

May 20, 2025
CVE-2025-37929
5.5

A missing sentinel entry in ARM64 Spectre-BHB workaround arrays in the Linux kernel causes a kernel panic during boot when UBSAN (Undefined Behavior S...

May 20, 2025
CVE-2025-37919
5.5

A NULL pointer dereference vulnerability in the Linux kernel's AMD ACP audio driver allows local attackers to cause a kernel panic (system crash) or p...

May 20, 2025
CVE-2025-37910
5.5

A NULL pointer dereference vulnerability in the Linux kernel's PTP (Precision Time Protocol) OCP driver for Adva boards can cause kernel crashes when ...

May 20, 2025
CVE-2025-37912
5.5

A null pointer dereference vulnerability exists in the Linux kernel's Intel Ethernet Connection (ice) driver. This allows a local attacker with VF (Vi...

May 20, 2025
CVE-2025-37894
5.5

A NULL pointer dereference vulnerability in the Linux kernel's networking subsystem occurs when sock_put() is incorrectly called on a struct inet_time...

May 20, 2025
CVE-2023-53146
5.5

This vulnerability in the Linux kernel's dw2102 media driver allows a local attacker to trigger a null pointer dereference by sending specially crafte...

May 14, 2025
CVE-2025-30320
5.5

Adobe InDesign versions ID19.5.2, ID20.2 and earlier contain a NULL pointer dereference vulnerability that allows attackers to cause denial-of-service...

May 13, 2025
CVE-2025-37853
5.5

A NULL pointer dereference vulnerability in the Linux kernel's AMD GPU driver (drm/amdkfd) allows local attackers to crash the kernel when accessing t...

May 9, 2025
CVE-2025-37841
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's cpupower benchmarking tool. If memory allocation fails, the system c...

May 9, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,252 CVEs classified as CWE-476, with 21 rated critical and 303 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free