CWE-476: NULL Pointer Dereference
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Yearly Trend
Top Affected Vendors
All NULL Pointer Dereference CVEs (1,273)
This vulnerability in NVIDIA DGX Spark GB10's SROOT firmware allows attackers to trigger a NULL pointer dereference, potentially causing a denial of s...
Nov 25, 2025A null pointer dereference vulnerability in Cesanta Mongoose's add_ca_certs() function allows remote attackers to cause denial of service by triggerin...
Nov 24, 2025A NULL pointer dereference vulnerability in OISM libcoap's DTLS implementation allows remote attackers to crash applications using the library via a s...
Nov 24, 2025A NULL pointer dereference vulnerability in OISM libcoap's DTLS cookie generation function allows remote attackers to cause denial of service. Attacke...
Nov 24, 2025A NULL pointer dereference vulnerability in OISM libcoap's DTLS implementation allows remote attackers to crash the application via a specially crafte...
Nov 24, 2025A NULL pointer dereference vulnerability in OISM libcoap's DTLS cookie generation function allows remote attackers to cause denial of service. Attacke...
Nov 24, 2025A null pointer dereference vulnerability in libcoap's DTLS handshake processing allows remote attackers to crash applications using the library. This ...
Nov 24, 2025A NULL pointer dereference vulnerability in radare2's bin_dyldcache.c load() function allows attackers to crash the program by processing a malicious ...
Nov 14, 2025A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing can cause an invalid pointer dereference when receiving a UDP/IPv6 packet...
Oct 10, 2025A denial-of-service vulnerability in libsoup HTTP client library allows attackers to crash client applications by sending crafted 401 responses with m...
May 16, 2025A vulnerability in Siemens SCALANCE LPE9403 industrial switches allows unauthenticated remote attackers to crash the dcpd process by sending specially...
May 13, 2025This vulnerability is a NULL pointer dereference in FFmpeg's MOV file format parser that can cause a denial of service (crash) when processing special...
Feb 18, 2025This CVE describes a NULL pointer dereference vulnerability in the MediaTek clock driver for the Linux kernel. If the mtk_alloc_clk_data() function fa...
May 21, 2024Open5GS v2.7.5 is vulnerable to a NULL pointer dereference when receiving multipart/related HTTP POST requests with empty bodies to its Service-Based ...
Sep 17, 2025This vulnerability in GnuPG allows an attacker to crash the application by sending a specially crafted signature packet with an excessive length. When...
Jan 27, 2026This vulnerability in libexpat's XML_ExternalEntityParserCreate function fails to copy unknown encoding handler user data, potentially causing crashes...
Jan 23, 2026A NULL pointer dereference vulnerability in FreeRDP's rdp_write_logon_info_v2() function allows a malicious RDP server to crash FreeRDP proxy instance...
Feb 9, 2026This vulnerability allows unauthenticated attackers to crash the HTTP service on Tapo C220 v1 and C520WS v2 cameras by sending POST requests with exce...
Jan 27, 2026A NULL pointer dereference vulnerability exists in the cJSON.Cpp module of SKRoot-linuxKernelRoot, which could cause denial of service or potential co...
Jan 27, 2026A NULL pointer dereference vulnerability in visualfc liteide's libvterm component allows attackers to cause denial of service by crashing the applicat...
Jan 27, 2026A NULL pointer dereference vulnerability in TP-Link Archer BE400 routers allows attackers on the same network to trigger a denial-of-service condition...
Jan 7, 2026A local privilege escalation vulnerability in Netskope's Windows agent allows authenticated users with Administrator privileges to improperly load a d...
Nov 28, 2025A bug in OSV-SCALIBR's filesystem traversal causes a panic when processing empty directories, leading to application crashes. This vulnerability affec...
Nov 20, 2025About NULL Pointer Dereference (CWE-476)
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Our database tracks 1,273 CVEs classified as CWE-476, with 24 rated critical and 321 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.
External reference: View CWE-476 on MITRE CWE →
Monitor NULL Pointer Dereference Vulnerabilities
Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.
Start Monitoring Free