CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,243
Total CVEs
20
Critical
295
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 16
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,243)

CVE-2021-32284
7.8

CVE-2021-32284 is a NULL pointer dereference vulnerability in gravity programming language versions through 0.8.1. An attacker can trigger this vulner...

Sep 20, 2021
CVE-2021-37688
7.8

This vulnerability allows attackers to craft malicious TFLite models that trigger a null pointer dereference in TensorFlow, causing a crash and denial...

Aug 12, 2021
CVE-2021-37648
7.8

This vulnerability in TensorFlow allows attackers to trigger a null pointer dereference in the SaveV2 operation, potentially causing denial of service...

Aug 12, 2021
CVE-2021-37681
7.8

This CVE describes a null pointer dereference vulnerability in TensorFlow's TFLite SVDF implementation. Attackers could cause denial of service or pot...

Aug 12, 2021
CVE-2019-14584
7.8

CVE-2019-14584 is a null pointer dereference vulnerability in Tianocore EDK2 firmware that allows an authenticated local user to potentially escalate ...

Jun 3, 2021
CVE-2020-35981
7.8

This vulnerability in GPAC multimedia framework allows attackers to cause denial of service or potentially execute arbitrary code by exploiting an inv...

Apr 21, 2021
CVE-2025-55698
7.7

A null pointer dereference vulnerability in Windows DirectX allows authenticated attackers to cause denial of service by crashing affected systems. Th...

Oct 14, 2025
CVE-2022-0908
7.7

This vulnerability in libtiff allows an attacker to cause denial of service by passing a null pointer to memcpy() when processing specially crafted TI...

Mar 11, 2022
CVE-2021-37637
7.7

This vulnerability in TensorFlow allows attackers to trigger a null pointer dereference by passing invalid input to the tf.raw_ops.CompressElement fun...

Aug 12, 2021
CVE-2021-37647
7.7

This vulnerability in TensorFlow allows attackers to cause a null pointer dereference by providing empty sparse tensor arguments to the SparseTensorSl...

Aug 12, 2021
CVE-2024-31755
7.6

CVE-2024-31755 is a NULL pointer dereference vulnerability in cJSON v1.7.17 that can cause segmentation faults when the cJSON_SetValuestring function ...

Apr 26, 2024
CVE-2022-21736
7.6

This vulnerability in TensorFlow's SparseTensorSliceDataset allows attackers to cause a null pointer dereference by providing invalid input arguments ...

Feb 3, 2022
CVE-2026-26025
7.5

A denial-of-service vulnerability in free5GC SMF allows attackers to crash the Session Management Function by sending malformed PFCP SessionReportRequ...

Feb 24, 2026
CVE-2026-2507
7.5

A vulnerability in BIG-IP AFM or BIG-IP DDoS modules causes the Traffic Management Microkernel (TMM) to terminate when processing specific undisclosed...

Feb 18, 2026
CVE-2025-70954
7.5

A Null Pointer Dereference vulnerability in TON Blockchain's TVM allows attackers to crash validator nodes by sending malicious transactions. This cau...

Feb 13, 2026
CVE-2026-21243
7.5

This vulnerability allows an unauthorized attacker to trigger a null pointer dereference in Windows LDAP service, causing a denial of service. Any Win...

Feb 10, 2026
CVE-2025-63655
7.5

This vulnerability allows attackers to crash Monkey web servers by sending specially crafted HTTP requests that trigger a NULL pointer dereference. An...

Jan 29, 2026
CVE-2025-69421
7.5

A NULL pointer dereference vulnerability in OpenSSL's PKCS12_item_decrypt_d2i_ex() function allows attackers to cause denial of service by providing m...

Jan 27, 2026
CVE-2025-63647
7.5

A NULL pointer dereference vulnerability in owntone-server's parse_meta function allows attackers to crash the server by sending a specially crafted D...

Jan 20, 2026
CVE-2025-63648
7.5

A NULL pointer dereference vulnerability in owntone-server's DACP handling allows attackers to crash the service by sending a specially crafted reques...

Jan 20, 2026
CVE-2025-57155
7.5

A NULL pointer dereference vulnerability in owntone-server's DAAP service allows remote attackers to crash the service by sending specially crafted re...

Jan 20, 2026
CVE-2025-57156
7.5

A NULL pointer dereference vulnerability in owntone-server's DACP reply handling allows remote attackers to crash the service by sending specially cra...

Jan 20, 2026
CVE-2026-0943
7.5

This vulnerability involves a null pointer dereference in the bundled HarfBuzz library within HarfBuzz::Shaper for Perl. It could allow attackers to c...

Jan 19, 2026
CVE-2026-20875
7.5

A null pointer dereference vulnerability in Windows LSASS allows attackers to cause a denial of service by crashing the service. This affects Windows ...

Jan 13, 2026
CVE-2025-53477
7.5

A NULL pointer dereference vulnerability in Apache NimBLE's Bluetooth stack occurs when HCI connection completion or command transmission buffers lack...

Jan 10, 2026
CVE-2025-56225
7.5

FluidSynth versions 2.4.6 and earlier contain a null pointer dereference vulnerability in fluid_synth_monopoly.c that can be triggered by loading a sp...

Jan 9, 2026
CVE-2025-65411
7.5

A NULL pointer dereference vulnerability in GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) by injecting a crafted payload into...

Dec 30, 2025
CVE-2025-14180
7.5

This vulnerability in PHP's PDO PostgreSQL driver causes a null pointer dereference when using prepared statements with invalid character sequences, l...

Dec 27, 2025
CVE-2025-14501
7.5

This vulnerability allows remote attackers to crash Sante PACS Server by sending specially crafted HTTP requests with malformed Content-Length headers...

Dec 23, 2025
CVE-2025-65566
7.5

A denial-of-service vulnerability in the omec-project UPF's pfcpiface component allows attackers to crash the UPF process by sending malformed PFCP Se...

Dec 18, 2025
CVE-2025-65565
7.5

A denial-of-service vulnerability in omec-project UPF's pfcpiface component allows attackers to crash the UPF process by sending malformed PFCP Sessio...

Dec 18, 2025
CVE-2025-65563
7.5

A denial-of-service vulnerability in omec-project UPF allows attackers to crash the UPF process by sending malformed PFCP Association Setup Request me...

Dec 18, 2025
CVE-2025-65564
7.5

A denial-of-service vulnerability in omec-upf's PFCP interface allows attackers to crash the UPF process by sending malformed PFCP Association Setup R...

Dec 18, 2025
CVE-2025-66646
7.5

A NULL pointer dereference vulnerability in RIOT OS's IPv6 fragmentation reassembly allows remote attackers to crash the operating system by sending s...

Dec 17, 2025
CVE-2025-68274
7.5

A nil pointer dereference vulnerability in SIPGO library's NewResponseFromRequest function allows remote attackers to crash SIP applications by sendin...

Dec 16, 2025
CVE-2025-64085
7.5

A NULL pointer dereference vulnerability in PDF-XChange Editor v10.7.3.401 allows attackers to crash the application via specially crafted PDF files, ...

Dec 9, 2025
CVE-2025-64086
7.5

A NULL pointer dereference vulnerability in PDF-XChange Editor's util.readFileIntoStream component allows attackers to crash the application via speci...

Dec 9, 2025
CVE-2025-14309
7.5

A NULL pointer dereference vulnerability in ravynOS allows attackers to cause denial of service or potentially execute arbitrary code by triggering a ...

Dec 9, 2025
CVE-2025-54326
7.5

A NULL pointer dereference vulnerability in Samsung Exynos 1280 and 2200 camera drivers allows attackers to cause denial of service by triggering a cr...

Dec 3, 2025
CVE-2025-7007
7.5

A NULL pointer dereference vulnerability in Avast Antivirus on macOS and Linux allows an attacker to crash the antivirus process by scanning a malform...

Dec 1, 2025
CVE-2025-65493
7.5

A NULL pointer dereference vulnerability in OISM libcoap 4.3.5 allows remote attackers to cause denial of service via crafted DTLS/TLS connections. Th...

Nov 24, 2025
CVE-2025-65494
7.5

A NULL pointer dereference vulnerability in OISM libcoap's certificate parsing function allows remote attackers to cause denial of service by sending ...

Nov 24, 2025
CVE-2025-63929
7.5

A null pointer dereference vulnerability in airpig2011 IEC104 allows concurrent threads to crash the application via segmentation fault, causing denia...

Nov 12, 2025
CVE-2025-59777
7.5

A NULL pointer dereference vulnerability in GNU libmicrohttpd v1.0.2 and earlier allows attackers to cause denial-of-service (DoS) by sending speciall...

Nov 10, 2025
CVE-2025-27917
7.5

This vulnerability allows remote attackers to cause a denial of service in AnyDesk clients through incorrect deserialization that leads to memory allo...

Nov 6, 2025
CVE-2025-46404
7.5

A denial of service vulnerability in Entr'ouvert Lasso's SAML signature verification allows attackers to crash the service by sending specially crafte...

Nov 5, 2025
CVE-2025-61107
7.5

A NULL pointer dereference vulnerability in FRRouting's OSPF implementation allows attackers to crash the routing daemon via specially crafted LSA Upd...

Oct 28, 2025
CVE-2025-61104
7.5

This vulnerability in FRRouting (FRR) allows attackers to cause a denial of service by sending a specially crafted OSPF packet that triggers a NULL po...

Oct 28, 2025
CVE-2025-61101
7.5

CVE-2025-61101 is a NULL pointer dereference vulnerability in FRRouting/frr that allows attackers to cause a Denial of Service (DoS) by sending a spec...

Oct 27, 2025
CVE-2025-61105
7.5

This vulnerability in FRRouting/frr allows attackers to cause a denial of service by sending a specially crafted OSPF packet that triggers a NULL poin...

Oct 27, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,243 CVEs classified as CWE-476, with 20 rated critical and 295 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free