CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,270
Total CVEs
23
Critical
319
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 22
5 Adobe 22
6 Microsoft 20
7 Qualcomm 20
8 Fedoraproject 19
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,270)

CVE-2022-48756
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's MSM DSI (Display Serial Interface) driver. The vulnerability occurs ...

Jun 20, 2024
CVE-2022-48746
5.5

A NULL pointer dereference vulnerability in the Linux kernel's mlx5e network driver allows a local attacker to cause a kernel panic (system crash) by ...

Jun 20, 2024
CVE-2022-48728
5.5

This vulnerability is a NULL pointer dereference in the Linux kernel's InfiniBand hfi1 driver that can cause a kernel panic during early initializatio...

Jun 20, 2024
CVE-2022-48718
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's mxsfb DRM driver. When exploited, it can cause kernel crashes or pot...

Jun 20, 2024
CVE-2021-47618
5.5

This vulnerability in the Linux kernel causes a kernel panic when both KASAN (Kernel Address Sanitizer) and kprobes are enabled on ARM32 systems. The ...

Jun 20, 2024
CVE-2021-47591
5.5

A null pointer dereference vulnerability in the Linux kernel's MPTCP implementation allows local attackers to crash the kernel when TCP_ULP setsockopt...

Jun 19, 2024
CVE-2021-47593
5.5

A Linux kernel vulnerability in the MPTCP (Multipath TCP) subsystem allows local users to crash the kernel through a NULL pointer dereference. When MP...

Jun 19, 2024
CVE-2024-38574
5.5

A null-pointer dereference vulnerability in the Linux kernel's libbpf library allows local attackers to cause denial of service (system crash) when lo...

Jun 19, 2024
CVE-2024-38543
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's lib/test_hmm.c module. If memory allocation fails during device evic...

Jun 19, 2024
CVE-2024-38547
5.5

A null-pointer dereference vulnerability in the Linux kernel's atomisp media subsystem allows local attackers to cause a kernel panic (denial of servi...

Jun 19, 2024
CVE-2024-30285
5.5

Adobe Audition versions 24.2, 23.6.4 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by tr...

Jun 13, 2024
CVE-2024-22524
5.5

CVE-2024-22524 is a buffer overflow vulnerability in dnspod-sr DNS software that could allow attackers to crash the service or potentially execute arb...

Jun 6, 2024
CVE-2024-36953
5.5

A NULL pointer dereference vulnerability in the Linux kernel's KVM (Kernel-based Virtual Machine) subsystem for ARM64 architecture. When handling GICv...

May 30, 2024
CVE-2024-36930
5.5

A null pointer dereference vulnerability in the Linux kernel's SPI subsystem allows local attackers to cause a kernel panic (denial of service) by reu...

May 30, 2024
CVE-2024-36938
5.5

A race condition vulnerability in the Linux kernel's BPF subsystem allows a NULL pointer dereference when processing socket messages. This can cause k...

May 30, 2024
CVE-2024-36926
5.5

A NULL pointer dereference vulnerability in the Linux kernel's powerpc/pseries/iommu code causes kernel panics during system boot when a frozen PCI Ex...

May 30, 2024
CVE-2024-36902
5.5

A NULL pointer dereference vulnerability in the Linux kernel's IPv6 routing subsystem allows attackers to cause a kernel panic (system crash) through ...

May 30, 2024
CVE-2024-36892
5.5

This Linux kernel vulnerability causes a 'Freepointer corrupt' detection when freeing single memory objects with specific kernel configurations enable...

May 30, 2024
CVE-2024-36023
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel that could cause a kernel panic or system crash. It affects Linux syst...

May 30, 2024
CVE-2024-36014
5.5

This CVE describes a null pointer dereference vulnerability in the ARM Mali Display Processor (MaliDP) driver of the Linux kernel. If exploited, it co...

May 29, 2024
CVE-2021-47552
5.5

A race condition vulnerability in the Linux kernel's block multi-queue (blk-mq) subsystem can cause a NULL pointer dereference when destroying storage...

May 24, 2024
CVE-2021-47557
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Enhanced Transmission Selection (ETS) queuing discipline allows local attackers to caus...

May 24, 2024
CVE-2021-47559
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's SMC (Shared Memory Communications) networking subsystem. When exploi...

May 24, 2024
CVE-2021-47540
5.5

A NULL pointer dereference vulnerability in the mt7915 wireless driver in the Linux kernel allows local attackers to cause a kernel panic (denial of s...

May 24, 2024
CVE-2021-47522
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's HID bigbenff driver. When emulating the device through uhid, the dri...

May 24, 2024
CVE-2021-47515
5.5

This Linux kernel vulnerability occurs when IPv4 packets are encapsulated in IPv6+SRH headers, causing the receiving interface index to be cleared fro...

May 24, 2024
CVE-2024-36011
5.5

This CVE-2024-36011 is a null pointer dereference vulnerability in the Linux kernel's Bluetooth HCI subsystem. It could allow local attackers to cause...

May 23, 2024
CVE-2021-47445
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's MSM DRM driver. An attacker could potentially cause a kernel panic o...

May 22, 2024
CVE-2021-47436
5.5

This CVE describes a kernel crash vulnerability in the Linux kernel's USB MUSB driver for DSPS platforms. When the probe function fails during device ...

May 22, 2024
CVE-2023-52850
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Hantro video processing driver could cause kernel panics or system crashes. This affect...

May 21, 2024
CVE-2023-52853
5.5

This vulnerability in the Linux kernel's cp2112 HID driver involves duplicate workqueue initialization during IRQ startup, which can trigger a kernel ...

May 21, 2024
CVE-2023-52856
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's lt8912b display bridge driver. When the bridge detaches (e.g., durin...

May 21, 2024
CVE-2023-52821
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's DRM panel driver. If exploited, it could cause a kernel panic or sys...

May 21, 2024
CVE-2023-52809
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's libfc module, specifically in the fc_lport_ptp_setup() function. If ...

May 21, 2024
CVE-2023-52814
5.5

This CVE is a null pointer dereference vulnerability in the AMD GPU driver within the Linux kernel. If exploited, it could cause a kernel panic or sys...

May 21, 2024
CVE-2023-52806
5.5

A null pointer dereference vulnerability in the Linux kernel's ALSA HDA subsystem allows local attackers to crash the system or potentially escalate p...

May 21, 2024
CVE-2023-52783
5.5

A null pointer dereference vulnerability in the Linux kernel's wangxun network driver causes kernel panic when devices use custom subsystem vendor IDs...

May 21, 2024
CVE-2023-52789
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's vcc driver. If kstrdup() fails during vcc_probe(), the system could ...

May 21, 2024
CVE-2023-52774
5.5

A race condition vulnerability in the Linux kernel's s390/dasd driver allows concurrent access to the device queue during profiling operations. This c...

May 21, 2024
CVE-2023-52779
5.5

A Linux kernel vulnerability in filesystem attribute handling causes a NULL pointer dereference when vfs_getattr_nosec() incorrectly calls vfs_getattr...

May 21, 2024
CVE-2023-52745
5.5

A NULL pointer dereference vulnerability in the Linux kernel's IP over InfiniBand (IPoIB) subsystem allows local attackers to cause a kernel panic and...

May 21, 2024
CVE-2023-52753
5.5

This CVE describes a NULL pointer dereference vulnerability in the AMD display driver component of the Linux kernel. An attacker could potentially cau...

May 21, 2024
CVE-2022-48708
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's pinctrl-single driver. If exploited, it could cause a kernel panic o...

May 21, 2024
CVE-2022-48710
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Radeon graphics driver. If exploited, it could cause a kernel panic ...

May 21, 2024
CVE-2021-47418
5.5

A NULL pointer dereference vulnerability in the Linux kernel's network scheduler allows local attackers to cause a kernel panic (denial of service) by...

May 21, 2024
CVE-2021-47397
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation. It allow...

May 21, 2024
CVE-2021-47399
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ixgbe network driver allows local attackers to cause a kernel panic (denial of service)...

May 21, 2024
CVE-2021-47385
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's w83792d hardware monitoring driver. When specific conditions are met...

May 21, 2024
CVE-2021-47380
5.5

This CVE describes a NULL pointer dereference vulnerability in the AMD SFH (Sensor Fusion Hub) driver in the Linux kernel. The vulnerability occurs wh...

May 21, 2024
CVE-2021-47331
5.5

A race condition in the Linux kernel's USB connector GPIO driver causes a NULL pointer dereference when an OTG cable is connected during system boot. ...

May 21, 2024

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,270 CVEs classified as CWE-476, with 23 rated critical and 319 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free