CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,259
Total CVEs
22
Critical
309
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 22
5 Adobe 21
6 Microsoft 20
7 Fedoraproject 19
8 Qualcomm 19
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,259)

CVE-2022-49195
5.5

A NULL pointer dereference vulnerability in the Linux kernel's DSA (Distributed Switch Architecture) subsystem causes kernel panics during system shut...

Feb 26, 2025
CVE-2022-49187
5.5

A NULL pointer dereference vulnerability in the Linux kernel's clock framework allows local attackers to cause a kernel panic (system crash) by trigge...

Feb 26, 2025
CVE-2022-49177
5.5

This CVE describes a NULL pointer dereference vulnerability in the Cavium hardware random number generator driver in the Linux kernel. If exploited, i...

Feb 26, 2025
CVE-2022-49165
5.5

A NULL pointer dereference vulnerability in the Linux kernel's i.MX JPEG decoder driver allows local attackers to crash the system by triggering a ker...

Feb 26, 2025
CVE-2022-49139
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Bluetooth subsystem allows local attackers to cause a kernel panic (denial of service) ...

Feb 26, 2025
CVE-2022-49134
5.5

A NULL pointer dereference vulnerability in the Linux kernel's mlxsw driver could cause kernel panics or system crashes when processing certain firmwa...

Feb 26, 2025
CVE-2022-49125
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's SPRD DRM driver. If exploited, it could cause a kernel panic or syst...

Feb 26, 2025
CVE-2022-49106
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's vchiq_arm driver. If exploited, it could cause a kernel panic leadin...

Feb 26, 2025
CVE-2022-49104
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's vchiq_core component. An attacker could cause a kernel panic or syst...

Feb 26, 2025
CVE-2022-49090
5.5

A race condition in the Linux kernel's ARM64 architecture prevents proper core scheduling topology initialization, causing incorrect CPU mask setup. T...

Feb 26, 2025
CVE-2022-49083
5.5

A NULL pointer dereference vulnerability in the Linux kernel's OMAP IOMMU driver allows local attackers to cause a kernel panic (denial of service). T...

Feb 26, 2025
CVE-2022-49072
5.5

A race condition vulnerability in the Linux kernel's GPIO subsystem allows uninitialized interrupt request (IRQ) members to be accessed before proper ...

Feb 26, 2025
CVE-2022-49060
5.5

A NULL pointer dereference vulnerability in the Linux kernel's SMC (Shared Memory Communications) networking subsystem allows local attackers to cause...

Feb 26, 2025
CVE-2022-49046
5.5

This CVE is a null pointer dereference vulnerability in the Linux kernel's i2c device subsystem. If dev_set_name() fails during i2c device creation, s...

Feb 26, 2025
CVE-2021-47645
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Zoran media driver allows local attackers to cause a kernel panic or system crash. This...

Feb 26, 2025
CVE-2021-47647
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Qualcomm IPQ8074 PCI-E clock driver. When the kernel attempts to acc...

Feb 26, 2025
CVE-2025-1470
5.5

This vulnerability in Eclipse OMR versions up to 0.4.0 allows NULL pointer dereference crashes when z/OS atoe functions fail to allocate memory. It af...

Feb 21, 2025
CVE-2025-24483
5.5

A NULL pointer dereference vulnerability in Defense Platform Home Edition allows attackers to cause a Blue Screen of Death (BSOD) and denial-of-servic...

Feb 6, 2025
CVE-2025-21670
5.5

A NULL pointer dereference vulnerability in the Linux kernel's vsock/bpf subsystem allows local attackers to cause a kernel panic (denial of service) ...

Jan 31, 2025
CVE-2025-21676
5.5

A NULL pointer dereference vulnerability in the Linux kernel's FEC (Fast Ethernet Controller) driver can cause kernel crashes when memory allocation f...

Jan 31, 2025
CVE-2024-57948
5.5

A race condition vulnerability in the Linux kernel's IEEE 802.15.4 (WPAN) subsystem allows a local attacker to cause a kernel panic (denial of service...

Jan 31, 2025
CVE-2025-21666
5.5

This CVE addresses a null pointer dereference vulnerability in the Linux kernel's vsock (virtual socket) subsystem. When a vsock socket is de-assigned...

Jan 31, 2025
CVE-2024-50665
5.5

This vulnerability in gpac's MP4Box tool is a NULL pointer dereference that causes a segmentation fault (SEGV) when processing specially crafted MP4 f...

Jan 23, 2025
CVE-2024-57933
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's GVE (Google Virtual Ethernet) driver when handling XSK (AF_XDP) oper...

Jan 21, 2025
CVE-2024-57927
5.5

A NULL pointer dereference vulnerability in the Linux kernel's NFS client implementation can cause kernel oops (system crash) when netfslib attempts t...

Jan 19, 2025
CVE-2025-21636
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation. When acc...

Jan 19, 2025
CVE-2025-21638
5.5

A NULL pointer dereference vulnerability in the Linux kernel's SCTP implementation allows local attackers to cause a kernel panic (denial of service) ...

Jan 19, 2025
CVE-2025-21640
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's SCTP subsystem. When the kernel accesses current->nsproxy (which can...

Jan 19, 2025
CVE-2025-21642
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's MPTCP subsystem when accessing network namespace data via current->n...

Jan 19, 2025
CVE-2025-21644
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Xe graphics driver occurs when the GuC firmware fails to load, causing the driver to we...

Jan 19, 2025
CVE-2025-21632
5.5

A Linux kernel vulnerability in x86 shadow stack ptrace handling allows unprivileged users to trigger a kernel warning (WARN_ON) when attempting to ac...

Jan 19, 2025
CVE-2024-36476
5.5

This CVE-2024-36476 is a NULL pointer dereference vulnerability in the Linux kernel's RDMA/rtrs subsystem. It can cause kernel panics and system crash...

Jan 15, 2025
CVE-2024-57881
5.5

A NULL pointer dereference vulnerability in the Linux kernel's memory management subsystem could cause kernel panics or system crashes when freeing me...

Jan 11, 2025
CVE-2024-57799
5.5

A race condition in the Linux kernel's Rockchip Samsung HDPTX PHY driver can cause a NULL pointer dereference during device initialization. This vulne...

Jan 11, 2025
CVE-2024-56372
5.5

A NULL pointer dereference vulnerability in the Linux kernel's TUN/TAP driver allows local attackers to cause a kernel panic (denial of service) by tr...

Jan 11, 2025
CVE-2024-48873
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's rtw89 WiFi driver. If exploited, this could cause a kernel panic or system crash...

Jan 11, 2025
CVE-2024-46896
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's AMD GPU driver. When a compute shader (CS) fails validation, the dri...

Jan 11, 2025
CVE-2024-56782
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ACPI subsystem. If exploited, it could cause a kernel panic leading ...

Jan 8, 2025
CVE-2024-56773
5.5

A NULL pointer dereference vulnerability in the Linux kernel's KUnit testing framework could cause kernel crashes or denial of service. This affects L...

Jan 8, 2025
CVE-2024-56767
5.5

A null pointer dereference vulnerability exists in the Linux kernel's AT_XDMAC DMA engine driver. When the at_xdmac_prep_dma_memset function receives ...

Jan 6, 2025
CVE-2024-56727
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's octeontx2-pf driver when handling mailbox responses. This could allow local atta...

Dec 29, 2024
CVE-2024-56711
5.5

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's DRM panel driver for Himax HX83102 displays. If exploited, it could ...

Dec 29, 2024
CVE-2024-56697
5.5

This CVE addresses a NULL pointer dereference vulnerability in the AMD GPU driver within the Linux kernel. An attacker could trigger a kernel panic or...

Dec 28, 2024
CVE-2024-56689
5.5

A NULL pointer dereference vulnerability in the Linux kernel's PCI endpoint MHI driver allows local attackers to cause a kernel panic (denial of servi...

Dec 28, 2024
CVE-2024-56667
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Intel graphics driver (drm/i915) could cause kernel crashes or denial of service when t...

Dec 27, 2024
CVE-2024-56660
5.5

A NULL pointer dereference vulnerability in the Linux kernel's mlx5 driver could cause kernel crashes or denial of service. This affects systems using...

Dec 27, 2024
CVE-2024-56646
5.5

A NULL pointer dereference vulnerability in the Linux kernel's IPv6 implementation allows local attackers to cause a kernel panic (denial of service) ...

Dec 27, 2024
CVE-2024-56621
5.5

A NULL pointer dereference vulnerability in the Linux kernel's UFS (Universal Flash Storage) driver allows local attackers to cause a kernel panic and...

Dec 27, 2024
CVE-2024-56612
5.5

A NULL pointer dereference vulnerability in the Linux kernel's unpin_user_pages() function can cause kernel crashes when handling certain memory confi...

Dec 27, 2024
CVE-2024-56599
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ath10k SDIO driver can cause kernel panic during module removal when CONFIG_INIT_ON_FRE...

Dec 27, 2024

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,259 CVEs classified as CWE-476, with 22 rated critical and 309 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free