CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,251
Total CVEs
20
Critical
303
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,251)

CVE-2020-17525
7.5

This vulnerability in Subversion's mod_authz_svn module causes a server crash when using in-repository authz rules with AuthzSVNReposRelativeAccessFil...

Mar 17, 2021
CVE-2021-28306
7.5

This vulnerability in the Rust fltk crate allows a NULL pointer dereference when using a multi label type with a nonexistent image. This can cause app...

Mar 12, 2021
CVE-2021-20274
7.5

This vulnerability in Privoxy allows a crash due to a NULL-pointer dereference when the SOCKS server behaves unexpectedly. It affects Privoxy versions...

Mar 9, 2021
CVE-2020-13583
7.5

A denial-of-service vulnerability in Micrium uC-HTTP 3.01.00 allows attackers to crash the HTTP server by sending specially crafted HTTP requests. Thi...

Feb 10, 2021
CVE-2020-13578
7.5

A denial-of-service vulnerability in Genivia gSOAP's WS-Security plugin allows attackers to crash affected services by sending specially crafted SOAP ...

Feb 10, 2021
CVE-2020-13574
7.5

This vulnerability in Genivia gSOAP's WS-Security plugin allows attackers to cause denial-of-service by sending specially crafted SOAP requests. Syste...

Feb 10, 2021
CVE-2021-25904
7.5

This vulnerability in the av-data Rust crate allows dereferencing of raw pointers, potentially reading arbitrary memory addresses. This can cause segm...

Jan 26, 2021
CVE-2020-27279
7.5

A NULL pointer dereference vulnerability in Crimson 3.1 protocol converter allows attackers to cause denial of service by sending specially crafted pa...

Jan 6, 2021
CVE-2025-68141
7.4

A null pointer dereference vulnerability in EVerest EV charging software allows remote attackers to cause denial of service by sending specially craft...

Jan 21, 2026
CVE-2025-29838
7.4

This vulnerability allows an unauthorized attacker to exploit a null pointer dereference in Windows Drivers to elevate privileges locally. It affects ...

May 13, 2025
CVE-2024-39356
7.4

A NULL pointer dereference vulnerability in Intel PROSet/Wireless WiFi and Killer WiFi software for Windows allows unauthenticated attackers on the sa...

Feb 12, 2025
CVE-2021-47464
7.4

This CVE describes a null-pointer dereference vulnerability in the Linux kernel's audit subsystem. The flaw in audit_filter_rules() could allow local ...

May 22, 2024
CVE-2025-57248
7.3

A null pointer dereference vulnerability in SumatraPDF 3.5.2 allows attackers to crash the application by tricking users into opening a malicious .djv...

Sep 15, 2025
CVE-2021-30272
7.3

A null pointer dereference vulnerability in Qualcomm Snapdragon thread cache operation handler allows attackers to cause denial of service or potentia...

Jan 3, 2022
CVE-2021-30270
7.3

This vulnerability in Qualcomm Snapdragon chipsets allows potential denial-of-service or arbitrary code execution due to a null pointer dereference in...

Jan 3, 2022
CVE-2024-57925
7.1

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ksmbd SMB server module. If exploited, it could lead to kernel crash...

Jan 19, 2025
CVE-2024-26672
7.1

This is a NULL pointer dereference vulnerability in the Linux kernel's AMD GPU driver. It allows local attackers to cause a kernel panic (denial of se...

Apr 2, 2024
CVE-2023-33036
7.1

This vulnerability allows an untrusted virtual machine without Power State Coordination Interface (PSCI) support to make a PSCI call, causing a perman...

Jan 2, 2024
CVE-2021-3739
7.1

A NULL pointer dereference vulnerability in the Linux kernel's Btrfs filesystem allows local attackers with CAP_SYS_ADMIN privileges to crash the syst...

Mar 10, 2022
CVE-2021-1935
7.1

This vulnerability in Qualcomm Snapdragon chipsets allows potential denial of service or arbitrary code execution due to a null pointer dereference du...

Sep 9, 2021
CVE-2021-1064
7.1

NVIDIA vGPU manager contains a vulnerability where it improperly handles untrusted input by converting it to a pointer and dereferencing it, potential...

Jan 8, 2021
CVE-2025-29547
7.0

This vulnerability in Rollback Rx Professional allows local users to trigger a null pointer dereference via a specific IOCtl call to the shieldm.sys d...

Apr 22, 2025
CVE-2024-35919
7.0

This CVE describes a NULL pointer dereference vulnerability in the MediaTek video codec driver of the Linux kernel. When the encoder context list is d...

May 19, 2024
CVE-2026-24918
6.8

This CVE describes a NULL pointer dereference vulnerability in Huawei communication modules that could cause denial of service. The vulnerability affe...

Feb 6, 2026
CVE-2025-31163
6.6

A segmentation fault vulnerability in fig2dev version 3.2.9a allows attackers to cause denial of service through local input manipulation via the put_...

Mar 28, 2025
CVE-2026-20064
6.5

A local authenticated attacker with low privileges can cause Cisco Secure Firewall Threat Defense devices to unexpectedly reload by sending crafted CL...

Mar 4, 2026
CVE-2025-54148
6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...

Feb 11, 2026
CVE-2025-53598
6.5

A NULL pointer dereference vulnerability in Qsync Central allows remote attackers with valid user credentials to cause a denial-of-service condition. ...

Feb 11, 2026
CVE-2025-54147
6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...

Feb 11, 2026
CVE-2025-47209
6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...

Feb 11, 2026
CVE-2025-30266
6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...

Feb 11, 2026
CVE-2025-68699
6.5

CVE-2025-68699 is a NULL pointer dereference vulnerability in NanoMQ MQTT Broker that allows remote attackers to crash the broker by sending a malform...

Feb 4, 2026
CVE-2026-23565
6.5

A vulnerability in TeamViewer DEX Client's Content Distribution Service (NomadBranch.exe) allows attackers on adjacent networks to crash the service v...

Jan 29, 2026
CVE-2026-23952
6.5

ImageMagick versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL parser when processing <comment> tags before images ar...

Jan 22, 2026
CVE-2026-21680
6.5

A NULL pointer dereference vulnerability in iccDEV library versions before 2.3.1.2 can cause application crashes or denial of service when processing ...

Jan 7, 2026
CVE-2025-20793
6.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...

Jan 6, 2026
CVE-2025-53592
6.5

A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial-of-service conditions. This a...

Jan 2, 2026
CVE-2025-44013
6.5

A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial-of-service conditions. This a...

Jan 2, 2026
CVE-2025-65296
6.5

A NULL-pointer dereference vulnerability in Aqara smart home hubs allows attackers to cause denial-of-service by sending malformed JSON inputs. This a...

Dec 10, 2025
CVE-2025-64527
6.5

Envoy proxy crashes when JWT authentication with remote JWKS fetching is configured, allow_missing_or_failed is enabled, multiple JWT tokens are prese...

Dec 3, 2025
CVE-2025-20750
6.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by having a ...

Dec 2, 2025
CVE-2025-65408
6.5

This vulnerability allows attackers to cause a denial of service by sending a specially crafted ADTS audio file to Live555 Streaming Media servers. Th...

Dec 1, 2025
CVE-2025-53408
6.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated attackers to cause denial-of-service by crashing the service. Thi...

Nov 7, 2025
CVE-2025-53412
6.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated remote attackers to cause denial-of-service by crashing the servi...

Nov 7, 2025
CVE-2025-47207
6.5

A NULL pointer dereference vulnerability in QNAP File Station allows authenticated attackers to cause denial-of-service conditions. This affects users...

Nov 7, 2025
CVE-2025-61908
6.5

This vulnerability in Icinga 2 allows any authenticated API user to crash the monitoring daemon by creating invalid references (like null references) ...

Oct 16, 2025
CVE-2025-44008
6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service by crashing the service. Th...

Oct 3, 2025
CVE-2025-44010
6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects al...

Oct 3, 2025
CVE-2025-30275
6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...

Aug 29, 2025
CVE-2025-30272
6.5

A NULL pointer dereference vulnerability in QNAP operating systems allows attackers to cause denial-of-service conditions by crashing affected systems...

Aug 29, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,251 CVEs classified as CWE-476, with 20 rated critical and 303 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free