CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,273
Total CVEs
24
Critical
321
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 22
5 Adobe 22
6 Microsoft 20
7 Qualcomm 20
8 Fedoraproject 19
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,273)

CVE-2025-33197
4.3

This vulnerability in NVIDIA DGX Spark GB10's SROOT firmware allows attackers to trigger a NULL pointer dereference, potentially causing a denial of s...

Nov 25, 2025
CVE-2025-65502
4.3

A null pointer dereference vulnerability in Cesanta Mongoose's add_ca_certs() function allows remote attackers to cause denial of service by triggerin...

Nov 24, 2025
CVE-2025-65496
4.3

A NULL pointer dereference vulnerability in OISM libcoap's DTLS implementation allows remote attackers to crash applications using the library via a s...

Nov 24, 2025
CVE-2025-65497
4.3

A NULL pointer dereference vulnerability in OISM libcoap's DTLS cookie generation function allows remote attackers to cause denial of service. Attacke...

Nov 24, 2025
CVE-2025-65498
4.3

A NULL pointer dereference vulnerability in OISM libcoap's DTLS implementation allows remote attackers to crash the application via a specially crafte...

Nov 24, 2025
CVE-2025-65500
4.3

A NULL pointer dereference vulnerability in OISM libcoap's DTLS cookie generation function allows remote attackers to cause denial of service. Attacke...

Nov 24, 2025
CVE-2025-65501
4.3

A null pointer dereference vulnerability in libcoap's DTLS handshake processing allows remote attackers to crash applications using the library. This ...

Nov 24, 2025
CVE-2025-63744
4.3

A NULL pointer dereference vulnerability in radare2's bin_dyldcache.c load() function allows attackers to crash the program by processing a malicious ...

Nov 14, 2025
CVE-2025-11618
4.3

A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing can cause an invalid pointer dereference when receiving a UDP/IPv6 packet...

Oct 10, 2025
CVE-2025-4476
4.3

A denial-of-service vulnerability in libsoup HTTP client library allows attackers to crash client applications by sending crafted 401 responses with m...

May 16, 2025
CVE-2025-40576
4.3

A vulnerability in Siemens SCALANCE LPE9403 industrial switches allows unauthenticated remote attackers to crash the dcpd process by sending specially...

May 13, 2025
CVE-2025-25471
4.3

This vulnerability is a NULL pointer dereference in FFmpeg's MOV file format parser that can cause a denial of service (crash) when processing special...

Feb 18, 2025
CVE-2023-52870
4.1

This CVE describes a NULL pointer dereference vulnerability in the MediaTek clock driver for the Linux kernel. If the mtk_alloc_clk_data() function fa...

May 21, 2024
CVE-2025-55904
4.0

Open5GS v2.7.5 is vulnerable to a NULL pointer dereference when receiving multipart/related HTTP POST requests with empty bodies to its Service-Based ...

Sep 17, 2025
CVE-2026-24883
3.7

This vulnerability in GnuPG allows an attacker to crash the application by sending a specially crafted signature packet with an excessive length. When...

Jan 27, 2026
CVE-2026-24515
2.9

This vulnerability in libexpat's XML_ExternalEntityParserCreate function fails to copy unknown encoding handler user data, potentially causing crashes...

Jan 23, 2026
CVE-2026-23948
N/A

A NULL pointer dereference vulnerability in FreeRDP's rdp_write_logon_info_v2() function allows a malicious RDP server to crash FreeRDP proxy instance...

Feb 9, 2026
CVE-2026-0918
N/A

This vulnerability allows unauthenticated attackers to crash the HTTP service on Tapo C220 v1 and C520WS v2 cameras by sending POST requests with exce...

Jan 27, 2026
CVE-2026-24813
N/A

A NULL pointer dereference vulnerability exists in the cJSON.Cpp module of SKRoot-linuxKernelRoot, which could cause denial of service or potential co...

Jan 27, 2026
CVE-2026-24805
N/A

A NULL pointer dereference vulnerability in visualfc liteide's libvterm component allows attackers to cause denial of service by crashing the applicat...

Jan 27, 2026
CVE-2025-14631
N/A

A NULL pointer dereference vulnerability in TP-Link Archer BE400 routers allows attackers on the same network to trigger a denial-of-service condition...

Jan 7, 2026
CVE-2025-11156
N/A

A local privilege escalation vulnerability in Netskope's Windows agent allows authenticated users with Administrator privileges to improperly load a d...

Nov 28, 2025
CVE-2025-13425
N/A

A bug in OSV-SCALIBR's filesystem traversal causes a panic when processing empty directories, leading to application crashes. This vulnerability affec...

Nov 20, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,273 CVEs classified as CWE-476, with 24 rated critical and 321 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free