CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,270
Total CVEs
23
Critical
319
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 22
5 Adobe 22
6 Microsoft 20
7 Qualcomm 20
8 Fedoraproject 19
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,270)

CVE-2021-47333
5.5

A NULL pointer dereference vulnerability in the Linux kernel's alcor_pci driver allows local attackers to cause a kernel panic (denial of service) whe...

May 21, 2024
CVE-2021-47340
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's JFS filesystem implementation. When the kernel attempts to free an i...

May 21, 2024
CVE-2021-47290
5.5

A NULL pointer dereference vulnerability in the Linux kernel's SCSI target subsystem allows local attackers to cause a kernel panic (denial of service...

May 21, 2024
CVE-2021-47279
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's Broadcom STB USB pinmap driver. If exploited, it could cause a kerne...

May 21, 2024
CVE-2021-47270
5.5

A null pointer dereference vulnerability in the Linux kernel's USB gadget subsystem affects multiple USB gadget drivers when 10Gbps USB cabling is use...

May 21, 2024
CVE-2024-35985
5.5

A Linux kernel vulnerability in the EEVDF scheduler allows a NULL pointer dereference due to integer overflow in reweight_eevdf(). This can cause kern...

May 20, 2024
CVE-2024-35946
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's rtw89 WiFi driver. When canceling a scan operation, the driver might...

May 19, 2024
CVE-2024-35917
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's BPF subsystem on s390x architecture. It allows local attackers to ca...

May 19, 2024
CVE-2024-35902
5.5

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's RDS (Reliable Datagram Sockets) subsystem. When cp (connection point...

May 19, 2024
CVE-2024-35904
5.5

A NULL pointer dereference vulnerability in the Linux kernel's SELinux subsystem occurs when kern_mount() fails during SELinux filesystem mounting. Th...

May 19, 2024
CVE-2024-35907
5.5

A NULL pointer dereference vulnerability in the mlxbf_gige driver of the Linux kernel allows a kernel panic when kdump is enabled and triggered. This ...

May 19, 2024
CVE-2024-35842
5.5

A NULL pointer dereference vulnerability in the Linux kernel's MediaTek ASoC (Audio System on Chip) subsystem could cause kernel panics when accessing...

May 17, 2024
CVE-2024-35851
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Bluetooth Qualcomm Atheros (qca) driver allows local attackers to cause a kernel panic ...

May 17, 2024
CVE-2023-52690
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's powerpc/powernv subsystem. If kasprintf() fails to allocate memory a...

May 17, 2024
CVE-2023-52695
5.5

A null pointer dereference vulnerability in the AMD display driver component of the Linux kernel could cause kernel crashes or system instability when...

May 17, 2024
CVE-2023-52686
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's powerpc/powernv subsystem. The opal_event_init() function fails to c...

May 17, 2024
CVE-2023-52673
5.5

This CVE describes a null pointer dereference vulnerability in the AMD display driver within the Linux kernel. When accessing debugfs, the system atte...

May 17, 2024
CVE-2022-48703
5.5

A NULL pointer dereference vulnerability in the Linux kernel's thermal/int340x_thermal driver allows local attackers to cause a kernel panic (denial o...

May 3, 2024
CVE-2022-48692
5.5

A NULL pointer dereference vulnerability in the Linux kernel's SRP (SCSI RDMA Protocol) driver allows local attackers to cause a kernel panic and syst...

May 3, 2024
CVE-2024-27079
5.5

This vulnerability is a NULL pointer dereference in the Linux kernel's Intel IOMMU driver that can cause kernel crashes during device release operatio...

May 1, 2024
CVE-2024-27051
5.5

This CVE addresses a NULL pointer dereference vulnerability in the Linux kernel's cpufreq driver for Broadcom STB AVS processors. If exploited, it cou...

May 1, 2024
CVE-2024-27060
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Thunderbolt subsystem allows local attackers to cause a kernel panic (denial of service...

May 1, 2024
CVE-2024-27038
5.5

A NULL pointer dereference vulnerability in the Linux kernel's clock framework allows local attackers to cause a kernel panic (denial of service). Thi...

May 1, 2024
CVE-2024-27044
5.5

This CVE describes a NULL pointer dereference vulnerability in the AMD display driver within the Linux kernel. If exploited, it could cause a kernel p...

May 1, 2024
CVE-2024-26997
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's DWC2 USB host controller driver. An attacker could potentially cause...

May 1, 2024
CVE-2024-26978
5.5

A NULL pointer dereference vulnerability in the Linux kernel's max310x serial driver allows local attackers to cause a kernel panic (denial of service...

May 1, 2024
CVE-2024-26943
5.5

This CVE addresses a null pointer dereference vulnerability in the Linux kernel's Nouveau driver for NVIDIA GPUs. If memory allocation fails during GP...

May 1, 2024
CVE-2023-52648
5.5

This is a null pointer dereference vulnerability in the Linux kernel's VMware graphics driver (vmwgfx). When switching plane states during cursor oper...

May 1, 2024
CVE-2022-44369
5.5

CVE-2022-44369 is a null pointer dereference vulnerability in NASM 2.16 development version that can cause denial of service through application crash...

Mar 29, 2023
CVE-2023-1628
5.5

This vulnerability in Jianming Antivirus allows local attackers to trigger a null pointer dereference in the kvcore.sys driver's IoControlCode handler...

Mar 25, 2023
CVE-2023-1631
5.5

This vulnerability in JiangMin Antivirus allows local attackers to trigger a null pointer dereference in the kernel driver kvcore.sys via a specific I...

Mar 25, 2023
CVE-2023-1583
5.5

A NULL pointer dereference vulnerability in the Linux kernel's io_uring subsystem allows unprivileged local users to trigger a system crash (kernel pa...

Mar 24, 2023
CVE-2023-51368
5.4

A NULL pointer dereference vulnerability in QNAP operating systems could allow attackers to crash affected systems via network requests, causing denia...

Sep 6, 2024
CVE-2024-37820
5.4

This vulnerability in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to cause a denial of service by triggering a nil pointer dereference in ...

Jun 25, 2024
CVE-2026-26983
5.3

This CVE describes a use-after-free vulnerability in ImageMagick's MSL interpreter when processing invalid <map> elements, causing crashes. It affects...

Feb 24, 2026
CVE-2026-25798
5.3

A NULL pointer dereference vulnerability in ImageMagick's ClonePixelCacheRepository function allows remote attackers to crash applications by providin...

Feb 24, 2026
CVE-2025-10256
5.3

A NULL pointer dereference vulnerability in FFmpeg's Firequalizer filter allows attackers to cause denial of service by crashing applications that pro...

Feb 18, 2026
CVE-2026-23831
5.3

This CVE describes a nil pointer dereference vulnerability in Rekor's entry implementation that can cause a panic when processing attacker-controlled ...

Jan 22, 2026
CVE-2026-22693
5.3

A null pointer dereference vulnerability in HarfBuzz text shaping engine allows attackers to cause a segmentation fault and crash applications using t...

Jan 10, 2026
CVE-2025-7700
5.3

This vulnerability in FFmpeg's ALS audio decoder allows attackers to cause denial of service by crashing applications that process specially crafted a...

Nov 7, 2025
CVE-2025-42902
5.3

This memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform allows unauthenticated attackers to crash work processes by sending co...

Oct 14, 2025
CVE-2025-59351
5.3

Dragonfly versions before 2.1.0 contain a nil pointer dereference vulnerability where code panics when a function returns an error but its first retur...

Sep 17, 2025
CVE-2025-57611
5.3

A null pointer dereference vulnerability in rust-ffmpeg's dump() method allows attackers to cause denial of service by triggering a crash when memory ...

Sep 2, 2025
CVE-2025-25473
5.3

A memory leak vulnerability exists in FFmpeg's avformat_free_context function, which fails to properly release allocated memory when freeing format co...

Feb 18, 2025
CVE-2025-0696
5.3

CVE-2025-0696 is a NULL pointer dereference vulnerability in Cesanta Frozen JSON parsing library versions before 1.7. Attackers can crash applications...

Jan 27, 2025
CVE-2020-9085
5.3

A NULL pointer dereference vulnerability in certain Huawei products allows attackers to cause denial of service by sending specially crafted POST mess...

Dec 27, 2024
CVE-2024-36626
5.3

A NULL pointer dereference vulnerability exists in PrestaShop 8.1.4's math_round function in Tools.php. This vulnerability could cause the application...

Nov 29, 2024
CVE-2024-47586
5.3

CVE-2024-47586 is a null pointer dereference vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform that allows unauthenticated ...

Nov 12, 2024
CVE-2024-35200
5.3

This vulnerability allows attackers to cause denial of service by sending specially crafted HTTP/3 requests to NGINX servers configured with the QUIC ...

May 29, 2024
CVE-2025-31711
5.1

A null pointer dereference vulnerability in the cplog service allows local attackers to crash the system without requiring elevated privileges. This a...

Jun 3, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,270 CVEs classified as CWE-476, with 23 rated critical and 319 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free