CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,249
Total CVEs
20
Critical
301
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,249)

CVE-2023-36199
7.5

This vulnerability in skalenetwork sgxwallet allows attackers to cause denial of service through the trustedGenerateEcdsaKey component. It affects all...

Aug 25, 2023
CVE-2022-28070
7.5

A null pointer dereference vulnerability in radare2's __core_anal_fcn function allows attackers to cause denial of service or potentially execute arbi...

Aug 22, 2023
CVE-2023-39669
7.5

CVE-2023-39669 is a NULL pointer dereference vulnerability in D-Link DIR-880 A1 routers that can cause denial of service or potentially allow remote c...

Aug 18, 2023
CVE-2023-39397
7.5

CVE-2023-39397 is a NULL pointer dereference vulnerability in Huawei/HarmonyOS communication systems where improper input validation allows attackers ...

Aug 13, 2023
CVE-2020-36138
7.5

This vulnerability in FFmpeg's TIFF decoder allows remote attackers to cause a denial of service by exploiting a NULL pointer dereference. It affects ...

Aug 11, 2023
CVE-2023-32252
7.5

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to cause a denial-of-service by sending specially crafted SMB2_LOGOFF comma...

Jul 24, 2023
CVE-2023-29984
7.5

A null pointer dereference vulnerability in Debut web server versions 1.2 and 1.3 allows attackers to cause denial-of-service conditions on affected M...

Jul 11, 2023
CVE-2023-32084
7.5

CVE-2023-32084 is a denial-of-service vulnerability in HTTP.sys, the Windows HTTP protocol stack. It allows remote attackers to crash affected systems...

Jul 11, 2023
CVE-2023-34164
7.5

This vulnerability in Huawei's communication framework module allows attackers to cause denial-of-service conditions by exploiting incomplete input pa...

Jul 6, 2023
CVE-2023-2953
7.5

This vulnerability in OpenLDAP causes a null pointer dereference in the ber_memalloc_x() function, which can lead to denial of service (DoS) by crashi...

May 30, 2023
CVE-2023-33973
7.5

CVE-2023-33973 is a NULL pointer dereference vulnerability in RIOT-OS's 6LoWPAN network stack that allows remote attackers to crash IoT devices by sen...

May 30, 2023
CVE-2023-29996
7.5

A null pointer dereference vulnerability in NanoMQ v0.15.0-0 causes segmentation faults when processing malformed MQTT subscription/unsubscription pac...

May 4, 2023
CVE-2022-33305
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm modems by sending specially crafted invalid messages on t...

May 2, 2023
CVE-2023-24822
7.5

CVE-2023-24822 is a NULL pointer dereference vulnerability in RIOT-OS's 6LoWPAN network stack that allows attackers to cause denial of service by send...

Apr 24, 2023
CVE-2023-24818
7.5

CVE-2023-24818 is a NULL pointer dereference vulnerability in RIOT-OS's 6LoWPAN network stack that allows attackers to cause denial of service by send...

Apr 24, 2023
CVE-2022-33223
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Qualcomm modems by sending specially crafted HTTP packets with chu...

Apr 13, 2023
CVE-2023-26917
7.5

This vulnerability is a NULL pointer dereference in libyang's lysp_stmt_validate_value function that can cause denial of service (crash) when processi...

Apr 11, 2023
CVE-2020-23259
7.5

This vulnerability in Jsish (a JavaScript interpreter for embedded systems) allows attackers to cause denial of service through a NULL pointer derefer...

Apr 4, 2023
CVE-2023-28625
7.5

CVE-2023-28625 is a NULL pointer dereference vulnerability in mod_auth_openidc for Apache HTTP Server when OIDCStripCookies is enabled. Attackers can ...

Apr 3, 2023
CVE-2022-3116
7.5

CVE-2022-3116 is a null pointer dereference vulnerability in Heimdal Kerberos 5 implementation. Attackers with network access to applications using vu...

Mar 27, 2023
CVE-2023-25676
7.5

This vulnerability in TensorFlow allows a denial of service attack through a null pointer dereference in the ParallelConcat operation when using XLA c...

Mar 25, 2023
CVE-2023-25670
7.5

This CVE describes a null pointer dereference vulnerability in TensorFlow's QuantizedMatMulWithBiasAndDequantize operation when MKL (Math Kernel Libra...

Mar 25, 2023
CVE-2023-25672
7.5

This vulnerability in TensorFlow's LookupTableImportV2 function causes a Null Pointer Exception (NPE) when scalar values are passed, potentially leadi...

Mar 25, 2023
CVE-2023-25674
7.5

This CVE describes a null pointer dereference vulnerability in TensorFlow's RandomShuffle operation when XLA (Accelerated Linear Algebra) is enabled. ...

Mar 25, 2023
CVE-2023-27785
7.5

CVE-2023-27785 is a NULL pointer dereference vulnerability in TCPreplay's tcprep utility that allows remote attackers to cause denial of service throu...

Mar 16, 2023
CVE-2023-27787
7.5

A NULL pointer dereference vulnerability in TCPprep v.4.4.3 allows remote attackers to cause denial of service by sending specially crafted input to t...

Mar 16, 2023
CVE-2022-25733
7.5

CVE-2022-25733 is a null pointer dereference vulnerability in Qualcomm modem firmware that allows denial of service attacks. When processing specially...

Feb 12, 2023
CVE-2022-25735
7.5

CVE-2022-25735 is a denial-of-service vulnerability in Qualcomm modems where missing null pointer checks when processing TCP/UDP packets can cause cra...

Feb 12, 2023
CVE-2023-0216
7.5

This CVE describes a NULL pointer dereference vulnerability in OpenSSL's PKCS7 parsing functions (d2i_PKCS7, d2i_PKCS7_bio, d2i_PKCS7_fp). When applic...

Feb 8, 2023
CVE-2022-32663
7.5

This vulnerability in MediaTek Wi-Fi drivers allows remote attackers to crash affected systems by exploiting a null pointer dereference. It affects de...

Feb 6, 2023
CVE-2022-31213
7.5

CVE-2022-31213 is a NULL pointer dereference vulnerability in dbus-broker that can cause crashes or potentially allow arbitrary code execution when pr...

Jul 17, 2022
CVE-2022-34761
7.5

A NULL pointer dereference vulnerability in Schneider Electric's X80 advanced RTU and OPC UA Modicon communication modules allows attackers to cause d...

Jul 13, 2022
CVE-2022-34735
7.5

This CVE describes a null pointer dereference vulnerability in the frame scheduling module of Huawei/HarmonyOS devices. Exploitation can cause kernel ...

Jul 12, 2022
CVE-2022-32230
7.5

CVE-2022-32230 is a denial-of-service vulnerability in Microsoft Windows SMBv3 where a malformed FileNormalizedNameInformation request causes a null p...

Jun 14, 2022
CVE-2021-35076
7.5

This vulnerability allows attackers to cause denial of service or potentially execute arbitrary code by sending a specially crafted RRC connection rec...

Jun 14, 2022
CVE-2021-33317
7.5

This vulnerability allows remote attackers to crash the LLDP process on TRENDnet TI-PG1284i switches by sending specially crafted LLDP packets that tr...

May 11, 2022
CVE-2022-1341
7.5

CVE-2022-1341 is a NULL pointer dereference vulnerability in bwm-ng v0.6.2 that allows attackers to cause a denial of service or potentially execute a...

Apr 18, 2022
CVE-2021-44498
7.5

This vulnerability in FIS GT.M (and related YottaDB) allows attackers to cause a denial-of-service crash through crafted input that triggers a NULL po...

Apr 15, 2022
CVE-2021-44506
7.5

This vulnerability in FIS GT.M (and related YottaDB) allows attackers to cause a NULL pointer dereference by corrupting a function pointer through imp...

Apr 15, 2022
CVE-2021-44508
7.5

This vulnerability in FIS GT.M (and related YottaDB) allows attackers to crash the application by triggering a NULL pointer dereference. It affects sy...

Apr 15, 2022
CVE-2021-44485
7.5

This CVE describes a NULL pointer dereference vulnerability in YottaDB that allows attackers to crash the application by triggering a NULL pointer acc...

Apr 15, 2022
CVE-2021-44492
7.5

This vulnerability in YottaDB and FIS GT.M database systems allows attackers to cause a crash via a NULL pointer dereference by sending crafted input ...

Apr 15, 2022
CVE-2021-44494
7.5

This vulnerability allows attackers to cause denial of service by crashing YottaDB or GT.M database systems through crafted input to ZRead commands. I...

Apr 15, 2022
CVE-2021-44108
7.5

This vulnerability in Open5GS allows remote attackers to cause a Denial of Service (DoS) by sending a specially crafted SBI request to the AMF compone...

Apr 5, 2022
CVE-2021-42577
7.5

This vulnerability in Softing OPC UA C++ SDK allows remote attackers to crash client applications by sending a specially crafted OPC/UA abort packet, ...

Mar 11, 2022
CVE-2021-43824
7.5

A crafted CONNECT request sent to Envoy's JWT filter configured with regex matching causes a crash, leading to denial of service. This affects Envoy d...

Feb 22, 2022
CVE-2022-0481
7.5

CVE-2022-0481 is a NULL pointer dereference vulnerability in mruby (a lightweight Ruby implementation) that can cause denial of service or potentially...

Feb 4, 2022
CVE-2022-22510
7.5

CVE-2022-22510 is a null pointer dereference vulnerability in Codesys Profinet V4.2.0.0 that allows unauthenticated attackers to cause denial of servi...

Feb 2, 2022
CVE-2022-23017
7.5

This vulnerability allows attackers to crash the Traffic Management Microkernel (TMM) on F5 BIG-IP systems by sending specially crafted DNS requests t...

Jan 25, 2022
CVE-2022-23021
7.5

This vulnerability in F5 BIG-IP allows attackers to cause denial of service by sending specially crafted requests to virtual servers with specific con...

Jan 25, 2022

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,249 CVEs classified as CWE-476, with 20 rated critical and 301 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free