CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,250
Total CVEs
20
Critical
302
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,250)

CVE-2021-38786
7.5

A NULL pointer dereference vulnerability in the media/libcedarc/vdecoder component of Allwinner R818 SoC Android Q SDK V1.0 allows attackers to cause ...

Jan 19, 2022
CVE-2021-45769
7.5

This vulnerability in libiec61850 v1.5.0 allows attackers to cause a denial of service by triggering a NULL pointer dereference in the AcseConnection_...

Jan 14, 2022
CVE-2021-40018
7.5

CVE-2021-40018 is a null pointer dereference vulnerability in the eID module of HarmonyOS, potentially allowing attackers to cause denial-of-service o...

Jan 10, 2022
CVE-2021-40031
7.5

This CVE describes a null pointer dereference vulnerability in the camera module of certain Huawei smartphones. Exploitation could allow attackers to ...

Jan 10, 2022
CVE-2021-39973
7.5

This CVE describes a null pointer dereference vulnerability in Huawei smartphones that could cause kernel crashes when exploited. It affects Huawei de...

Jan 3, 2022
CVE-2020-23026
7.5

This CVE describes a NULL pointer dereference vulnerability in dhrystone 2.1's dhry_1.c file that causes the program to crash, resulting in denial of ...

Jan 3, 2022
CVE-2021-45266
7.5

A null pointer dereference vulnerability in gpac 1.1.0 allows attackers to cause a segmentation fault and crash the application by exploiting the lsr_...

Dec 22, 2021
CVE-2021-4110
7.5

CVE-2021-4110 is a NULL pointer dereference vulnerability in mruby, a lightweight implementation of the Ruby programming language. This vulnerability ...

Dec 15, 2021
CVE-2021-37083
7.5

This CVE describes a NULL pointer dereference vulnerability in Huawei smartphones that can cause denial of service attacks when exploited. The vulnera...

Dec 7, 2021
CVE-2021-28236
7.5

LibreDWG v0.12.3 contains a NULL pointer dereference vulnerability in out_dxfb.c that can cause denial of service (DoS) through application crashes. T...

Dec 2, 2021
CVE-2021-39921
7.5

A NULL pointer dereference vulnerability in Wireshark's Modbus dissector allows attackers to cause denial of service via specially crafted Modbus pack...

Nov 19, 2021
CVE-2021-39920
7.5

A NULL pointer dereference vulnerability in Wireshark's IPPUSB dissector allows attackers to cause denial of service via specially crafted network pac...

Nov 18, 2021
CVE-2021-43667
7.5

A denial-of-service vulnerability in Hyperledger Fabric allows attackers to crash leader nodes by sending specially crafted nil payload messages via t...

Nov 18, 2021
CVE-2020-23879
7.5

CVE-2020-23879 is a NULL pointer dereference vulnerability in pdf2json v0.71 that can cause denial of service (DoS) through application crashes. This ...

Nov 10, 2021
CVE-2020-23872
7.5

CVE-2020-23872 is a NULL pointer dereference vulnerability in pdf2xml v2.0 that allows attackers to cause a denial of service (DoS) by crashing the ap...

Nov 10, 2021
CVE-2021-34586
7.5

CVE-2021-34586 is a null pointer dereference vulnerability in the CODESYS V2 web server that allows crafted web requests to cause denial-of-service co...

Oct 26, 2021
CVE-2021-23139
7.5

A null pointer dereference vulnerability in Trend Micro Apex One and Worry-Free Business Security allows attackers to crash the CGI program on affecte...

Oct 21, 2021
CVE-2021-1936
7.5

This vulnerability is a null pointer dereference in Qualcomm Snapdragon chipsets that can cause denial of service or potential code execution. It affe...

Oct 20, 2021
CVE-2021-32971
7.5

A null pointer dereference vulnerability in the SuiteLink server allows attackers to cause denial of service by sending a specially crafted command 0x...

Sep 23, 2021
CVE-2021-32987
7.5

A null pointer dereference vulnerability in the SuiteLink server allows attackers to crash the service by sending a specially crafted command 0x0b. Th...

Sep 23, 2021
CVE-2021-30698
7.5

This CVE describes a null pointer dereference vulnerability in Apple's macOS, iOS, iPadOS, and Safari that could allow a remote attacker to cause a de...

Sep 8, 2021
CVE-2021-22792
7.5

A NULL pointer dereference vulnerability in Schneider Electric Modicon PLC controllers and simulators allows denial of service attacks when processing...

Sep 2, 2021
CVE-2020-18731
7.5

A NULL pointer dereference vulnerability in IEC104 v1.0 allows attackers to cause a denial of service via segmentation violation. This affects systems...

Aug 23, 2021
CVE-2020-23330
7.5

A NULL pointer dereference vulnerability in Bento4's AP4_Stz2Atom::GetSampleSize function allows attackers to cause denial of service by crashing the ...

Aug 17, 2021
CVE-2021-38567
7.5

This vulnerability in Foxit PDF software on macOS allows attackers to cause a crash via NULL pointer dereference by exploiting mishandled missing dict...

Aug 11, 2021
CVE-2021-29294
7.5

A null pointer dereference vulnerability in D-Link DSL-2740R routers allows remote attackers to cause denial of service by sending crafted POST reques...

Aug 10, 2021
CVE-2021-29296
7.5

A null pointer dereference vulnerability in D-Link DIR-825 routers allows remote attackers to cause denial of service by sending a specially crafted H...

Aug 10, 2021
CVE-2021-28842
7.5

A null pointer dereference vulnerability in TRENDnet wireless access points allows remote attackers to cause denial of service by sending a specially ...

Aug 10, 2021
CVE-2021-28844
7.5

This vulnerability allows remote attackers to cause a denial-of-service (DoS) condition by sending a specially crafted POST request to the apply_cgi e...

Aug 10, 2021
CVE-2021-28838
7.5

A null pointer dereference vulnerability in D-Link DAP series access points allows remote attackers to crash the httpd service by sending specially cr...

Aug 10, 2021
CVE-2021-28840
7.5

A null pointer dereference vulnerability in D-Link DAP series access points allows remote attackers to crash the httpd service via a specially crafted...

Aug 10, 2021
CVE-2021-36764
7.5

CVE-2021-36764 is a NULL pointer dereference vulnerability in CODESYS Gateway V3 that allows attackers to cause denial-of-service conditions by sendin...

Aug 4, 2021
CVE-2021-25804
7.5

A NULL-pointer dereference vulnerability in VLC Media Player's AVI file handling can cause the application to crash when opening a specially crafted A...

Jul 26, 2021
CVE-2010-4816
7.5

A null pointer dereference vulnerability in the FTP daemon (ftpd) of affected FreeBSD and OpenBSD systems allows remote attackers to crash the ftpd se...

Jun 22, 2021
CVE-2021-0555
7.5

This CVE describes a null pointer dereference vulnerability in Android's protostream_objectsource.cc component. An attacker can remotely crash affecte...

Jun 22, 2021
CVE-2021-34555
7.5

CVE-2021-34555 is a denial-of-service vulnerability in OpenDMARC where remote attackers can crash the application by sending email messages with multi...

Jun 10, 2021
CVE-2020-13950
7.5

CVE-2020-13950 is a NULL pointer dereference vulnerability in Apache HTTP Server's mod_proxy_http module that allows remote attackers to cause a denia...

Jun 10, 2021
CVE-2021-26690
7.5

CVE-2021-26690 is a NULL pointer dereference vulnerability in Apache HTTP Server's mod_session module that can be triggered by a specially crafted Coo...

Jun 10, 2021
CVE-2021-27630
7.5

CVE-2021-27630 is a denial-of-service vulnerability in SAP NetWeaver ABAP Server and ABAP Platform Enqueue Server. An unauthenticated attacker can sen...

Jun 9, 2021
CVE-2021-27632
7.5

CVE-2021-27632 is a denial-of-service vulnerability in SAP NetWeaver ABAP Server and ABAP Platform's Enqueue Server. An unauthenticated attacker can s...

Jun 9, 2021
CVE-2021-27607
7.5

CVE-2021-27607 is a denial-of-service vulnerability in SAP NetWeaver ABAP Server and ABAP Platform that allows unauthenticated attackers to crash the ...

Jun 9, 2021
CVE-2020-18395
7.5

CVE-2020-18395 is a NULL pointer dereference vulnerability in GNU Gama's ellipsoid.h component that allows attackers to cause denial of service throug...

May 28, 2021
CVE-2020-20450
7.5

CVE-2020-20450 is a null pointer dereference vulnerability in FFmpeg 4.2's libavformat/aviobuf.c component that can cause a denial of service. Attacke...

May 25, 2021
CVE-2021-28683
7.5

This vulnerability in Envoy proxy allows remote attackers to cause a denial of service by sending a specially crafted TLS alert with an unknown alert ...

May 20, 2021
CVE-2021-3480
7.5

CVE-2021-3480 is a NULL pointer dereference vulnerability in slapi-nis that allows unauthenticated attackers to crash the 389-ds-base directory server...

May 20, 2021
CVE-2021-25693
7.5

CVE-2021-25693 is a null pointer dereference vulnerability in Teradici PCoIP Agent that allows attackers to cause a Denial of Service (DoS) by crashin...

May 13, 2021
CVE-2021-32611
7.5

This vulnerability is a NULL pointer dereference in eXosip2's eXcall_api.c that can be triggered by processing certain 3xx redirect responses. It affe...

May 12, 2021
CVE-2021-25845
7.5

This vulnerability allows attackers to cause a denial of service on Moxa VPort 06EC-2V Series IP cameras by sending a specially crafted LLDP packet. T...

May 10, 2021
CVE-2020-28346
7.5

CVE-2020-28346 is a NULL pointer dereference vulnerability in ACRN hypervisor's virtio.c PCI device model. This allows attackers to cause denial of se...

Mar 26, 2021
CVE-2021-20213
7.5

This vulnerability in Privoxy allows a denial-of-service attack when specific conditions are met. If accept-intercepted-requests is enabled and Privox...

Mar 25, 2021

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,250 CVEs classified as CWE-476, with 20 rated critical and 302 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free