CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,271
Total CVEs
24
Critical
319
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 22
5 Adobe 22
6 Microsoft 20
7 Qualcomm 20
8 Fedoraproject 19
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,271)

CVE-2025-31711
5.1

A null pointer dereference vulnerability in the cplog service allows local attackers to crash the system without requiring elevated privileges. This a...

Jun 3, 2025
CVE-2025-0287
5.1

This vulnerability in Paragon Software's biontdrv.sys driver allows attackers to execute arbitrary code in the kernel through a null pointer dereferen...

Mar 3, 2025
CVE-2024-6157
5.1

A NULL pointer dereference vulnerability in the PROFINET stack of ABB RobotWare allows attackers to cause denial of service by sending specially craft...

Oct 10, 2024
CVE-2024-9484
5.1

A null pointer dereference vulnerability in AVG/Avast Antivirus for macOS allows attackers to crash the antivirus application by processing a speciall...

Oct 4, 2024
CVE-2025-23332
5.0

The NVIDIA Display Driver for Linux contains a null pointer dereference vulnerability in a kernel module. An attacker could trigger this to cause a de...

Oct 23, 2025
CVE-2022-40733
5.0

This CVE describes an access violation vulnerability in the DirectComposition functionality of the win32kbase.sys driver on Windows 11 and Windows Ser...

Dec 18, 2024
CVE-2024-43520
5.0

This Windows kernel vulnerability allows attackers to cause a denial of service (system crash/BSOD) by exploiting a NULL pointer dereference. It affec...

Oct 8, 2024
CVE-2026-0401
4.9

A post-authentication NULL pointer dereference vulnerability in SonicOS firewalls allows authenticated remote attackers to cause a denial of service b...

Feb 24, 2026
CVE-2025-11847
4.9

An authenticated attacker with administrator privileges can cause a denial-of-service condition on affected Zyxel devices by sending a specially craft...

Feb 24, 2026
CVE-2025-11845
4.9

A null pointer dereference vulnerability in Zyxel networking devices allows authenticated administrators to trigger a denial-of-service condition by s...

Feb 24, 2026
CVE-2025-59386
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Feb 11, 2026
CVE-2025-53596
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-53405
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-53414
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-53589
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-53590
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-52426
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-52430
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-52431
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Jan 2, 2026
CVE-2025-52862
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52854
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52857
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52859
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52432
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52853
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-48729
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52424
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-52428
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-47214
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-48727
4.9

A NULL pointer dereference vulnerability in QNAP operating systems allows remote attackers with administrator credentials to cause denial-of-service c...

Oct 3, 2025
CVE-2025-8402
4.9

This vulnerability allows system administrators to crash Mattermost servers by importing malformed data through the bulk import feature. It affects Ma...

Aug 21, 2025
CVE-2024-11499
4.9

An authenticated attacker can trigger a restart of RTU500 CMU units by updating certificates during active connections. This affects RTU500 IEC 60870-...

Mar 25, 2025
CVE-2024-37048
4.9

A NULL pointer dereference vulnerability in QNAP operating systems could allow remote attackers with administrator access to crash the system, causing...

Nov 22, 2024
CVE-2024-22653
4.8

This CVE describes a NULL pointer dereference vulnerability in Yasm, an assembler used for compiling code. When exploited, it can cause the yasm proce...

May 29, 2025
CVE-2023-53401
4.7

This CVE describes a race condition in the Linux kernel's memory management subsystem where concurrent access to stock->cached_objcg pointer can cause...

Sep 18, 2025
CVE-2022-49295
4.7

A race condition vulnerability in the Linux kernel's NBD (Network Block Device) driver that can cause a NULL pointer dereference when the nbd module i...

Feb 26, 2025
CVE-2025-21695
4.7

A race condition in the Linux kernel's dell-uart-backlight driver can cause a NULL pointer dereference when the serdev controller attempts to access u...

Feb 12, 2025
CVE-2025-21685
4.7

A race condition in the Linux kernel's Lenovo Yoga Tab 2 Pro 1380 fast charger driver can cause a NULL pointer dereference when the serial device port...

Feb 9, 2025
CVE-2024-50277
4.7

A NULL pointer dereference vulnerability in the Linux kernel's device mapper (dm) subsystem causes a kernel crash when blk_alloc_disk fails during dev...

Nov 19, 2024
CVE-2024-46851
4.7

This CVE describes a race condition vulnerability in the Linux kernel's AMD display driver (drm/amd/display). When dc_state_destruct() runs parallel t...

Sep 27, 2024
CVE-2024-32666
4.7

A NULL pointer dereference vulnerability in Intel RAID Web Console software allows authenticated users with local access to cause denial of service by...

Sep 16, 2024
CVE-2024-46693
4.7

A race condition vulnerability in Linux kernel's Qualcomm PMIC Glink drivers allows NULL pointer dereference during initialization. This can cause ker...

Sep 13, 2024
CVE-2022-48751
4.7

A race condition vulnerability in the Linux kernel's SMC (Shared Memory Communications) subsystem allows NULL pointer dereference when accessing a rel...

Jun 20, 2024
CVE-2024-35954
4.7

A race condition in the Linux kernel's SCSI generic (sg) driver can cause a NULL pointer dereference when removing SCSI devices. This vulnerability al...

May 20, 2024
CVE-2024-27040
4.7

This CVE describes a NULL pointer dereference vulnerability in the AMD display driver within the Linux kernel. If exploited, it could cause a kernel p...

May 1, 2024
CVE-2023-30755
4.4

A vulnerability in Siemens SIMATIC industrial control devices allows remote attackers with elevated privileges to cause denial of service by exploitin...

Sep 10, 2024
CVE-2024-38559
4.4

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's QLogic FastLinQ 4xxxx Ethernet Controller driver (qedf). An attacker...

Jun 19, 2024
CVE-2024-36928
4.4

A NULL pointer dereference vulnerability in the Linux kernel's s390/qeth driver causes kernel panic when setting the hsuid attribute on an IQD Layer3 ...

May 30, 2024
CVE-2025-33197
4.3

This vulnerability in NVIDIA DGX Spark GB10's SROOT firmware allows attackers to trigger a NULL pointer dereference, potentially causing a denial of s...

Nov 25, 2025
CVE-2025-65502
4.3

A null pointer dereference vulnerability in Cesanta Mongoose's add_ca_certs() function allows remote attackers to cause denial of service by triggerin...

Nov 24, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,271 CVEs classified as CWE-476, with 24 rated critical and 319 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free