CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,248
Total CVEs
20
Critical
300
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,248)

CVE-2024-38232
7.5

CVE-2024-38232 is a Windows networking vulnerability that allows attackers to cause denial of service by sending specially crafted network packets. Th...

Sep 10, 2024
CVE-2024-45239
7.5

This vulnerability in FORT RPKI validator allows a malicious RPKI repository to crash the software by serving ROA or Manifest objects with null eConte...

Aug 24, 2024
CVE-2024-37399
7.5

This vulnerability allows remote unauthenticated attackers to cause a denial of service (DoS) by crashing the WLAvalancheService in Ivanti Avalanche. ...

Aug 14, 2024
CVE-2024-38146
7.5

This vulnerability in the Windows Layer-2 Bridge Network Driver allows an attacker to cause a denial of service (system crash/BSOD) by sending special...

Aug 13, 2024
CVE-2024-37826
7.5

A NULL pointer dereference vulnerability in vercot Serva v4.6.0 allows attackers to crash the service via specially crafted HTTP requests, causing den...

Aug 12, 2024
CVE-2024-39948
7.5

This vulnerability in Dahua products allows attackers to cause denial of service by sending specially crafted packets to vulnerable interfaces. The de...

Jul 31, 2024
CVE-2024-38536
7.5

A memory allocation failure in Suricata's HTTP inspection module leads to a NULL pointer dereference and crash when the http.memcap limit is reached. ...

Jul 11, 2024
CVE-2024-38072
7.5

CVE-2024-38072 is a denial-of-service vulnerability in the Windows Remote Desktop Licensing Service where specially crafted packets can cause the serv...

Jul 9, 2024
CVE-2024-39130
7.5

A NULL pointer dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to crash the application by triggering the DumpOneStream() function...

Jun 27, 2024
CVE-2024-36972
7.5

A race condition vulnerability in the Linux kernel's AF_UNIX socket implementation allows a NULL pointer dereference when handling out-of-band (OOB) d...

Jun 10, 2024
CVE-2024-35492
7.5

This vulnerability in Cesanta Mongoose allows attackers to cause a Denial of Service (DoS) by sending a specially crafted MQTT packet that triggers a ...

May 29, 2024
CVE-2024-35618
7.5

This vulnerability in PingCAP TiDB v7.5.1 involves a NULL pointer dereference in the SortedRowContainer component, which can cause the database servic...

May 24, 2024
CVE-2023-52696
7.5

This CVE is a NULL pointer dereference vulnerability in the Linux kernel's powerpc/powernv subsystem. The opal_powercap_init() function fails to check...

May 17, 2024
CVE-2024-27405
7.5

A vulnerability in the Linux kernel's USB gadget NCM driver causes properly parsed network datagrams to be dropped when Windows 11 sends extra padding...

May 17, 2024
CVE-2024-25560
7.5

A denial-of-service vulnerability in BIG-IP AFM where specific DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate, resulting ...

May 8, 2024
CVE-2024-34088
7.5

This vulnerability in FRRouting (FRR) allows attackers to cause a denial of service by triggering a NULL pointer dereference in the OSPF daemon. When ...

Apr 30, 2024
CVE-2024-32661
7.5

FreeRDP clients prior to version 3.5.1 contain a NULL pointer dereference vulnerability that can cause crashes when processing certain RDP traffic. Th...

Apr 23, 2024
CVE-2023-48183
7.5

This vulnerability in QuickJS (a JavaScript engine) allows a NULL pointer dereference when using 'eval' with 'for-in' loops due to incorrect lexical s...

Apr 23, 2024
CVE-2024-31041
7.5

A null pointer dereference vulnerability in NanoMQ's topic_filtern function allows attackers to crash the MQTT broker by sending specially crafted mes...

Apr 17, 2024
CVE-2024-26854
7.5

This CVE describes a race condition in the Linux kernel's Intel Ethernet Controller E800 Series driver (ice) where a mutex is used before being proper...

Apr 17, 2024
CVE-2024-3858
7.5

This vulnerability allows an attacker to crash Firefox by manipulating JavaScript objects to trigger a JIT (Just-In-Time) compiler failure. It affects...

Apr 16, 2024
CVE-2024-28458
7.5

A Null Pointer Dereference vulnerability in swfdump within swftools 0.9.2 allows attackers to crash the application by exploiting the compileSWFAction...

Apr 11, 2024
CVE-2024-23076
7.5

This CVE describes a potential NullPointerException in JFreeChart v1.5.4's BubbleXYItemLabelGenerator component, which could cause application crashes...

Apr 10, 2024
CVE-2024-22052
7.5

A null pointer dereference vulnerability in the IPSec component of Ivanti Connect Secure and Policy Secure gateways allows unauthenticated attackers t...

Apr 4, 2024
CVE-2023-45931
7.5

CVE-2023-45931 is a disputed NULL pointer dereference vulnerability in Mesa's check_xshm() function when the has_error state is triggered. This could ...

Mar 27, 2024
CVE-2024-27229
7.5

This vulnerability is a null pointer dereference in Android's call barring component that could allow remote attackers to cause denial of service with...

Mar 11, 2024
CVE-2023-29180
7.5

A null pointer dereference vulnerability in Fortinet FortiOS and FortiProxy allows attackers to cause denial of service via specially crafted HTTP req...

Feb 22, 2024
CVE-2024-26130
7.5

This vulnerability in the Python cryptography package causes a NULL pointer dereference when pkcs12.serialize_key_and_certificates is called with mism...

Feb 21, 2024
CVE-2024-24989
7.5

This vulnerability allows attackers to cause denial of service by sending specially crafted requests to NGINX servers with HTTP/3 QUIC module enabled....

Feb 14, 2024
CVE-2024-24775
7.5

This vulnerability in F5 BIG-IP systems causes a denial-of-service condition when specific network configurations are present. Attackers can crash the...

Feb 14, 2024
CVE-2024-23327
7.5

A NULL pointer dereference vulnerability in Envoy proxy when PPv2 is enabled on both listener and cluster configurations causes a segmentation fault w...

Feb 9, 2024
CVE-2023-43522
7.5

This vulnerability in Qualcomm chipsets allows a denial-of-service attack when processing empty or NULL encrypted keys during key unwrapping. It affec...

Feb 6, 2024
CVE-2023-46838
7.5

This vulnerability in Xen's virtual network protocol allows a NULL pointer dereference in Linux kernel networking code when processing specially craft...

Jan 29, 2024
CVE-2024-21602
7.5

A NULL pointer dereference vulnerability in Juniper Junos OS Evolved allows unauthenticated attackers to cause denial of service by sending specific I...

Jan 12, 2024
CVE-2024-20661
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows an attacker to send specially crafted malicious packets to cause a denial of service con...

Jan 9, 2024
CVE-2023-37187
7.5

CVE-2023-37187 is a NULL pointer dereference vulnerability in c-blosc2's zfp compression module that can cause denial of service (crash) when processi...

Dec 25, 2023
CVE-2023-37185
7.5

CVE-2023-37185 is a NULL pointer dereference vulnerability in c-blosc2's zfp_prec_decompress function that can cause denial of service (crash) when pr...

Dec 25, 2023
CVE-2023-50472
7.5

CVE-2023-50472 is a NULL pointer dereference vulnerability in cJSON v1.7.16 that can cause segmentation faults when the cJSON_SetValuestring function ...

Dec 14, 2023
CVE-2023-49936
7.5

This CVE describes a NULL pointer dereference vulnerability in SchedMD Slurm workload manager that can cause denial of service. When exploited, it cra...

Dec 14, 2023
CVE-2023-48416
7.5

This CVE describes a null pointer dereference vulnerability in Android Pixel devices that could allow remote attackers to cause denial of service with...

Dec 8, 2023
CVE-2023-33089
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted WLAN packets that trigger a NULL pointer...

Dec 5, 2023
CVE-2023-38315
7.5

CVE-2023-38315 is a NULL pointer dereference vulnerability in OpenNDS Captive Portal that allows remote attackers to cause a denial-of-service conditi...

Nov 17, 2023
CVE-2023-38322
7.5

This vulnerability in OpenNDS Captive Portal allows remote attackers to cause a denial-of-service by sending a crafted HTTP request with a missing Use...

Nov 17, 2023
CVE-2023-33056
7.5

This vulnerability allows a denial-of-service attack against WLAN firmware when it receives a specially crafted beacon frame containing a T2LM (Target...

Nov 7, 2023
CVE-2023-46345
7.5

Catdoc v0.95 contains a NULL pointer dereference vulnerability in the xls2csv component that can cause the application to crash when processing malici...

Oct 26, 2023
CVE-2023-38171
7.5

This vulnerability in Microsoft's QUIC protocol implementation allows attackers to cause denial of service by sending specially crafted network packet...

Oct 10, 2023
CVE-2023-36709
7.5

This vulnerability in Microsoft's AllJoyn API allows attackers to cause a denial of service (DoS) by sending specially crafted packets to vulnerable s...

Oct 10, 2023
CVE-2023-36603
7.5

CVE-2023-36603 is a Windows TCP/IP stack vulnerability that allows remote attackers to cause a denial of service (system crash/BSOD) by sending specia...

Oct 10, 2023
CVE-2023-41909
7.5

This vulnerability in FRRouting FRR allows remote attackers to cause a denial of service (crash) by sending specially crafted BGP flowspec requests wi...

Sep 5, 2023
CVE-2023-41358
7.5

A NULL pointer dereference vulnerability in FRRouting's BGP daemon allows remote attackers to cause denial of service by sending specially crafted BGP...

Aug 29, 2023

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,248 CVEs classified as CWE-476, with 20 rated critical and 300 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free