CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,268
Total CVEs
23
Critical
317
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 22
5 Adobe 22
6 Microsoft 20
7 Qualcomm 20
8 Fedoraproject 19
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,268)

CVE-2024-42266
5.5

A race condition vulnerability in the Linux kernel's Btrfs filesystem can cause a kernel panic when handling write errors. This affects systems using ...

Aug 17, 2024
CVE-2024-41866
5.5

Adobe InDesign has a NULL pointer dereference vulnerability that allows attackers to crash the application by tricking users into opening malicious fi...

Aug 14, 2024
CVE-2024-39395
5.5

Adobe InDesign has a NULL pointer dereference vulnerability that allows attackers to crash the application by tricking users into opening malicious fi...

Aug 14, 2024
CVE-2024-34137
5.5

Adobe Illustrator versions 28.5, 27.9.4 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by...

Aug 14, 2024
CVE-2024-42255
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's TPM (Trusted Platform Module) subsystem. When TCG_TPM2_HMAC is enabl...

Aug 8, 2024
CVE-2024-42248
5.5

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's ma35d1 serial driver. If exploited, it could cause a kernel panic or...

Aug 7, 2024
CVE-2024-42144
5.5

This CVE addresses a NULL pointer dereference vulnerability in the MediaTek LVTS thermal driver in the Linux kernel. If exploited, it could cause a ke...

Jul 30, 2024
CVE-2024-42149
5.5

This CVE addresses a race condition in the Linux kernel's filesystem thaw operations that can cause misleading warnings and potential system instabili...

Jul 30, 2024
CVE-2024-42151
5.5

A Linux kernel BPF subsystem vulnerability where the verifier could incorrectly optimize away NULL pointer checks in certain BPF programs, potentially...

Jul 30, 2024
CVE-2024-42134
5.5

A NULL pointer dereference vulnerability in the Linux kernel's virtio-pci driver allows local attackers to crash the guest system by triggering a kern...

Jul 30, 2024
CVE-2024-42125
5.5

A NULL pointer dereference vulnerability in the Linux kernel's rtw89 WiFi driver could cause kernel crashes when systems with BIOS policies blocking 6...

Jul 30, 2024
CVE-2024-42100
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's sunxi-ng clock controller driver. The flaw occurs when the driver in...

Jul 30, 2024
CVE-2024-42079
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's GFS2 filesystem. When unmounting a GFS2 filesystem while glock work ...

Jul 29, 2024
CVE-2024-42081
5.5

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's Xe graphics driver devcoredump component. The vulnerability could al...

Jul 29, 2024
CVE-2024-42083
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ionic network driver allows kernel panic when handling multi-buffer packets with XDP_TX...

Jul 29, 2024
CVE-2024-42074
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's AMD ACP audio driver. When the system resumes from suspend mode, a m...

Jul 29, 2024
CVE-2024-41089
5.5

A null pointer dereference vulnerability in the Linux kernel's NVIDIA display driver (nouveau) could cause kernel crashes or denial of service. This a...

Jul 29, 2024
CVE-2024-41098
5.5

A null pointer dereference vulnerability in the Linux kernel's libata-core component can cause kernel crashes when ata_port_alloc() fails during ata_h...

Jul 29, 2024
CVE-2024-41083
5.5

This Linux kernel vulnerability allows a NULL pointer dereference in the netfs subsystem when handling mmap'd writes during DIO (Direct I/O) operation...

Jul 29, 2024
CVE-2024-41085
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's CXL (Compute Express Link) subsystem. When the kernel attempts to au...

Jul 29, 2024
CVE-2024-41077
5.5

A vulnerability in the Linux kernel's null_blk driver allows improper validation of block size parameters. Attackers could trigger a null pointer dere...

Jul 29, 2024
CVE-2024-41836
5.5

This CVE describes a NULL pointer dereference vulnerability in Adobe InDesign that allows attackers to cause a denial-of-service by crashing the appli...

Jul 23, 2024
CVE-2022-48841
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Intel Ethernet Connection Controller (ice) driver. When the ice_upda...

Jul 16, 2024
CVE-2022-48824
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's myrs SCSI driver. When hardware initialization fails, the driver attempts to cal...

Jul 16, 2024
CVE-2022-48811
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ibmvnic driver can cause kernel crashes when network interface operations fail. This af...

Jul 16, 2024
CVE-2022-48793
5.5

This CVE describes a NULL pointer dereference vulnerability in the KVM (Kernel-based Virtual Machine) subsystem of the Linux kernel. During nested vir...

Jul 16, 2024
CVE-2024-40960
5.5

A NULL pointer dereference vulnerability in the Linux kernel's IPv6 routing subsystem allows local attackers to cause a kernel panic (denial of servic...

Jul 12, 2024
CVE-2024-40962
5.5

A NULL pointer dereference vulnerability in the Linux kernel's BTRFS filesystem for zoned storage devices can cause kernel panics and system crashes w...

Jul 12, 2024
CVE-2024-40964
5.5

A null pointer dereference vulnerability exists in the Linux kernel's ALSA HDA driver for CS35L41 audio codecs. When a device with index 0 is unbound,...

Jul 12, 2024
CVE-2024-40947
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's IMA (Integrity Measurement Architecture) subsystem. The vulnerability occurs w...

Jul 12, 2024
CVE-2024-40951
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's OCFS2 filesystem driver. When triggered, it causes a kernel panic th...

Jul 12, 2024
CVE-2024-40945
5.5

A Linux kernel vulnerability in the iommu_sva_bind_device() function could potentially cause a kernel NULL pointer dereference if the function returns...

Jul 12, 2024
CVE-2024-40911
5.5

A race condition vulnerability in the Linux kernel's WiFi subsystem allows a NULL pointer dereference when accessing wireless station statistics. This...

Jul 12, 2024
CVE-2024-40919
5.5

A NULL pointer dereference vulnerability exists in the bnxt_en driver of the Linux kernel when logging firmware messages. This occurs when a token is ...

Jul 12, 2024
CVE-2024-39504
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's netfilter nft_inner component. Attackers can trigger a kernel crash ...

Jul 12, 2024
CVE-2024-39506
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's liquidio network driver. The flaw occurs in the lio_vf_rep_copy_pack...

Jul 12, 2024
CVE-2024-39473
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Sound Open Firmware (SOF) subsystem allows local attackers to cause a kernel panic or s...

Jul 5, 2024
CVE-2024-39466
5.5

A null pointer dereference vulnerability in the Linux kernel's Qualcomm LMH thermal driver occurs when the driver fails to check for SCM (Secure Chann...

Jun 25, 2024
CVE-2024-39371
5.5

A NULL pointer dereference vulnerability in the Linux kernel's io_uring subsystem allows local attackers to cause a kernel panic (denial of service) b...

Jun 25, 2024
CVE-2024-39464
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's V4L2 async notifier subsystem. When csi2_async_register() fails (e.g...

Jun 25, 2024
CVE-2024-35247
5.5

A null pointer dereference vulnerability in the Linux kernel's FPGA region subsystem could allow local attackers to cause a kernel panic (denial of se...

Jun 24, 2024
CVE-2024-37021
5.5

A null pointer dereference vulnerability in the Linux kernel's FPGA manager subsystem could cause kernel crashes or denial of service. This affects sy...

Jun 24, 2024
CVE-2024-38637
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Greybus lights subsystem. If exploited, it could cause a kernel pani...

Jun 21, 2024
CVE-2024-38633
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's MAX3100 serial driver. When the last MAX3100 device is removed and t...

Jun 21, 2024
CVE-2024-38625
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's NTFS3 filesystem driver. When the 'bmap' function is called, it can pass a NULL ...

Jun 21, 2024
CVE-2024-36270
5.5

A NULL pointer dereference vulnerability in the Linux kernel's netfilter tproxy module allows local attackers to cause a kernel panic (denial of servi...

Jun 21, 2024
CVE-2024-38390
5.5

This vulnerability is a null pointer dereference in the Linux kernel's MSM A6xx GPU driver that occurs when speedbin setting fails during initializati...

Jun 21, 2024
CVE-2022-48749
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's MSM DPU display driver. An attacker could potentially cause a kernel...

Jun 20, 2024
CVE-2022-48756
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's MSM DSI (Display Serial Interface) driver. The vulnerability occurs ...

Jun 20, 2024
CVE-2022-48746
5.5

A NULL pointer dereference vulnerability in the Linux kernel's mlx5e network driver allows a local attacker to cause a kernel panic (system crash) by ...

Jun 20, 2024

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,268 CVEs classified as CWE-476, with 23 rated critical and 317 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free