CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,245
Total CVEs
20
Critical
297
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 16
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,245)

CVE-2025-61099
7.5

A NULL pointer dereference vulnerability in FRRouting's OSPF implementation allows attackers to crash the frr daemon via specially crafted LS Update p...

Oct 27, 2025
CVE-2025-50950
7.5

Audiofile v0.3.7 contains a NULL pointer dereference vulnerability in the ModuleState::setup function. This can cause denial of service (crash) when p...

Oct 23, 2025
CVE-2025-60336
7.5

A NULL pointer dereference vulnerability in TOTOLINK N600R routers allows attackers to crash the device via specially crafted HTTP requests, causing a...

Oct 22, 2025
CVE-2025-60335
7.5

A NULL pointer dereference vulnerability in TOTOLINK N600R routers allows attackers to crash the device via specially crafted HTTP requests, causing a...

Oct 22, 2025
CVE-2025-62409
7.5

This vulnerability in Envoy proxy allows large requests/responses to trigger TCP connection pool crashes when connections close while upstream data is...

Oct 16, 2025
CVE-2025-61960
7.5

A vulnerability in F5 BIG-IP APM allows undisclosed traffic to cause the Traffic Management Microkernel (TMM) to terminate when per-request policies a...

Oct 15, 2025
CVE-2025-59150
7.5

A NULL pointer dereference vulnerability in Suricata's TLS subject alternative name parsing causes segmentation faults when processing malicious TLS c...

Oct 1, 2025
CVE-2025-59668
7.5

A NULL pointer dereference vulnerability in Central Monitor CNS-6201 allows remote attackers to crash the device by sending a specially crafted UDP pa...

Sep 30, 2025
CVE-2025-55780
7.5

A null pointer dereference vulnerability in MuPDF's EPUB rendering function allows attackers to crash the application by providing a malformed EPUB do...

Sep 23, 2025
CVE-2025-36894
7.5

This vulnerability allows remote attackers to cause a denial of service (DoS) in affected systems without requiring authentication or user interaction...

Sep 4, 2025
CVE-2025-57612
7.5

A null pointer dereference vulnerability in rust-ffmpeg's name() method allows attackers to cause denial of service by triggering a crash. This affect...

Sep 2, 2025
CVE-2025-40779
7.5

A denial-of-service vulnerability in ISC Kea DHCPv4 server where a malicious DHCP client sending unicast requests with specific options can cause the ...

Aug 27, 2025
CVE-2025-52585
7.5

A vulnerability in F5 BIG-IP LTM allows remote attackers to cause denial of service by sending specially crafted requests to virtual servers with spec...

Aug 13, 2025
CVE-2025-53010
7.5

MaterialX versions before 1.39.3 contain a null pointer dereference vulnerability when parsing malicious MTLX files. This allows attackers to crash ap...

Aug 1, 2025
CVE-2025-8183
7.5

A NULL pointer dereference vulnerability in ยตD3TN allows remote attackers to cause a denial-of-service (DoS) by sending specially crafted non-singlet...

Jul 25, 2025
CVE-2025-53817
7.5

A null pointer dereference vulnerability in 7-Zip's Compound Document handler allows attackers to cause denial of service by crashing the application ...

Jul 17, 2025
CVE-2025-45333
7.5

CVE-2025-45333 is a Null Pointer Dereference vulnerability in berkeley-abc's abc 1.1 software that causes segmentation faults and program crashes when...

Jun 25, 2025
CVE-2025-45332
7.5

CVE-2025-45332 is a Null Pointer Dereference vulnerability in vkoskiv c-ray 1.1's parse_mtllib function that causes program crashes when processing ma...

Jun 25, 2025
CVE-2025-29876
7.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated attackers to cause denial-of-service by crashing the service. Thi...

Jun 6, 2025
CVE-2025-23100
7.5

A NULL pointer dereference vulnerability in Samsung Exynos mobile processors allows attackers to cause a denial of service by triggering a system cras...

Jun 3, 2025
CVE-2024-54952
7.5

MikroTik RouterOS 6.40.5 contains a memory corruption vulnerability in its SMB service. Remote, unauthenticated attackers can send specially crafted p...

May 29, 2025
CVE-2025-45835
7.5

A null pointer dereference vulnerability in Netis WF2880 routers allows attackers to cause denial-of-service by manipulating the CONTENT_LENGTH enviro...

May 12, 2025
CVE-2025-32398
7.5

A NULL pointer dereference vulnerability in RT-Labs P-Net library versions 1.0.1 and earlier allows remote attackers to crash industrial control syste...

May 7, 2025
CVE-2025-30195
7.5

This vulnerability in PowerDNS Recursor allows attackers to publish malicious DNS zones containing specific Resource Record Sets. Processing these rec...

Apr 7, 2025
CVE-2024-48615
7.5

A null pointer dereference vulnerability in libarchive 3.7.6 and earlier allows attackers to cause denial of service (crash) when processing specially...

Mar 28, 2025
CVE-2025-0312
7.5

A null pointer dereference vulnerability in Ollama versions up to 0.3.14 allows attackers to upload specially crafted GGUF model files that crash the ...

Mar 20, 2025
CVE-2024-41338
7.5

A NULL pointer dereference vulnerability in multiple Draytek router models allows attackers to cause Denial of Service (DoS) via specially crafted DHC...

Feb 27, 2025
CVE-2025-25475
7.5

A NULL pointer dereference vulnerability in DCMTK's DICOM file processing component allows attackers to cause denial of service by sending specially c...

Feb 18, 2025
CVE-2024-50608
7.5

CVE-2024-50608 is a NULL pointer dereference vulnerability in Fluent Bit's Prometheus Remote Write input plugin that allows remote denial of service a...

Feb 18, 2025
CVE-2024-50609
7.5

CVE-2024-50609 is a NULL pointer dereference vulnerability in Fluent Bit's OpenTelemetry input plugin that allows remote denial of service attacks. Wh...

Feb 18, 2025
CVE-2023-34398
7.5

A null pointer dereference vulnerability in the Boost library used by Mercedes-Benz NTG6 head units allows potential denial of service or arbitrary co...

Feb 13, 2025
CVE-2024-46922
7.5

A null pointer dereference vulnerability in Samsung Exynos 1480 and 2400 mobile processors' Xclipse GPU driver allows attackers to cause denial of ser...

Feb 12, 2025
CVE-2025-20045
7.5

This vulnerability allows an attacker to cause a denial of service by sending specially crafted SIP traffic to F5 BIG-IP systems with specific ALG con...

Feb 5, 2025
CVE-2025-24177
7.5

A null pointer dereference vulnerability in Apple operating systems allows remote attackers to cause denial-of-service conditions. This affects macOS,...

Jan 27, 2025
CVE-2024-24442
7.5

A NULL pointer dereference vulnerability in OpenAirInterface's 5G AMF software allows attackers to crash the service by sending specially crafted NGAP...

Jan 21, 2025
CVE-2025-0430
7.5

CVE-2025-0430 is a NULL pointer dereference vulnerability in Belledonne Communications Linphone-Desktop that allows remote attackers to cause denial-o...

Jan 17, 2025
CVE-2025-21285
EPSS 26.9% 7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service condition by sending specially crafted packets to...

Jan 14, 2025
CVE-2023-6603
7.5

This vulnerability in FFmpeg's HLS playlist parsing allows attackers to cause denial of service by triggering a null pointer dereference during initia...

Dec 31, 2024
CVE-2024-56318
7.5

A NULL pointer dereference vulnerability in Matter (Project CHIP) allows remote attackers to cause denial of service by sending specially crafted TCP ...

Dec 18, 2024
CVE-2024-53580
7.5

CVE-2024-53580 is a NULL pointer dereference vulnerability in iperf v3.17.1 that causes a segmentation fault via the iperf_exchange_parameters() funct...

Dec 18, 2024
CVE-2024-36832
7.5

This vulnerability allows unauthenticated attackers to crash the D-Link DAP-1513 wireless access point by sending a specially crafted HTTP request, ca...

Dec 17, 2024
CVE-2024-47599
7.5

A null pointer dereference vulnerability in GStreamer's JPEG decoder can cause segmentation faults when processing malformed JPEG files. This leads to...

Dec 12, 2024
CVE-2024-44854
7.5

CVE-2024-44854 is a NULL pointer dereference vulnerability in ROS2 navigation2's smoothPlan() function that can cause denial of service or potentially...

Dec 6, 2024
CVE-2024-44856
7.5

CVE-2024-44856 is a NULL pointer dereference vulnerability in ROS2 navigation2's nav2_smac_planner component that can cause denial of service. This af...

Dec 6, 2024
CVE-2024-11148
7.5

This vulnerability allows remote attackers to cause a denial-of-service (DoS) by sending a malformed FastCGI request to OpenBSD's httpd server. The NU...

Dec 5, 2024
CVE-2024-45969
7.5

A NULL pointer dereference vulnerability in MZ Automation's LibIEC61850 MMS Client allows a malicious MMS server to crash the client via a specially c...

Nov 15, 2024
CVE-2024-2550
7.5

An unauthenticated attacker can send a specially crafted packet to Palo Alto Networks PAN-OS GlobalProtect gateways, causing a null pointer dereferenc...

Nov 14, 2024
CVE-2024-50317
7.5

A null pointer dereference vulnerability in Ivanti Avalanche allows remote unauthenticated attackers to crash the service, causing denial of service. ...

Nov 12, 2024
CVE-2024-27532
7.5

A NULL pointer dereference vulnerability in wasm-micro-runtime's block_type_get_result_types function allows attackers to cause denial of service or p...

Nov 8, 2024
CVE-2024-22733
7.5

This vulnerability allows unauthenticated attackers to cause a denial of service on TP-Link MR200 V4 routers by sending specially crafted requests to ...

Nov 1, 2024

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,245 CVEs classified as CWE-476, with 20 rated critical and 297 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free