CWE-476: NULL Pointer Dereference
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Yearly Trend
Top Affected Vendors
All NULL Pointer Dereference CVEs (1,251)
This vulnerability in Subversion's mod_authz_svn module causes a server crash when using in-repository authz rules with AuthzSVNReposRelativeAccessFil...
Mar 17, 2021This vulnerability in the Rust fltk crate allows a NULL pointer dereference when using a multi label type with a nonexistent image. This can cause app...
Mar 12, 2021This vulnerability in Privoxy allows a crash due to a NULL-pointer dereference when the SOCKS server behaves unexpectedly. It affects Privoxy versions...
Mar 9, 2021A denial-of-service vulnerability in Micrium uC-HTTP 3.01.00 allows attackers to crash the HTTP server by sending specially crafted HTTP requests. Thi...
Feb 10, 2021A denial-of-service vulnerability in Genivia gSOAP's WS-Security plugin allows attackers to crash affected services by sending specially crafted SOAP ...
Feb 10, 2021This vulnerability in Genivia gSOAP's WS-Security plugin allows attackers to cause denial-of-service by sending specially crafted SOAP requests. Syste...
Feb 10, 2021This vulnerability in the av-data Rust crate allows dereferencing of raw pointers, potentially reading arbitrary memory addresses. This can cause segm...
Jan 26, 2021A NULL pointer dereference vulnerability in Crimson 3.1 protocol converter allows attackers to cause denial of service by sending specially crafted pa...
Jan 6, 2021A null pointer dereference vulnerability in EVerest EV charging software allows remote attackers to cause denial of service by sending specially craft...
Jan 21, 2026This vulnerability allows an unauthorized attacker to exploit a null pointer dereference in Windows Drivers to elevate privileges locally. It affects ...
May 13, 2025A NULL pointer dereference vulnerability in Intel PROSet/Wireless WiFi and Killer WiFi software for Windows allows unauthenticated attackers on the sa...
Feb 12, 2025This CVE describes a null-pointer dereference vulnerability in the Linux kernel's audit subsystem. The flaw in audit_filter_rules() could allow local ...
May 22, 2024A null pointer dereference vulnerability in SumatraPDF 3.5.2 allows attackers to crash the application by tricking users into opening a malicious .djv...
Sep 15, 2025A null pointer dereference vulnerability in Qualcomm Snapdragon thread cache operation handler allows attackers to cause denial of service or potentia...
Jan 3, 2022This vulnerability in Qualcomm Snapdragon chipsets allows potential denial-of-service or arbitrary code execution due to a null pointer dereference in...
Jan 3, 2022This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ksmbd SMB server module. If exploited, it could lead to kernel crash...
Jan 19, 2025This is a NULL pointer dereference vulnerability in the Linux kernel's AMD GPU driver. It allows local attackers to cause a kernel panic (denial of se...
Apr 2, 2024This vulnerability allows an untrusted virtual machine without Power State Coordination Interface (PSCI) support to make a PSCI call, causing a perman...
Jan 2, 2024A NULL pointer dereference vulnerability in the Linux kernel's Btrfs filesystem allows local attackers with CAP_SYS_ADMIN privileges to crash the syst...
Mar 10, 2022This vulnerability in Qualcomm Snapdragon chipsets allows potential denial of service or arbitrary code execution due to a null pointer dereference du...
Sep 9, 2021NVIDIA vGPU manager contains a vulnerability where it improperly handles untrusted input by converting it to a pointer and dereferencing it, potential...
Jan 8, 2021This vulnerability in Rollback Rx Professional allows local users to trigger a null pointer dereference via a specific IOCtl call to the shieldm.sys d...
Apr 22, 2025This CVE describes a NULL pointer dereference vulnerability in the MediaTek video codec driver of the Linux kernel. When the encoder context list is d...
May 19, 2024This CVE describes a NULL pointer dereference vulnerability in Huawei communication modules that could cause denial of service. The vulnerability affe...
Feb 6, 2026A segmentation fault vulnerability in fig2dev version 3.2.9a allows attackers to cause denial of service through local input manipulation via the put_...
Mar 28, 2025A local authenticated attacker with low privileges can cause Cisco Secure Firewall Threat Defense devices to unexpectedly reload by sending crafted CL...
Mar 4, 2026A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...
Feb 11, 2026A NULL pointer dereference vulnerability in Qsync Central allows remote attackers with valid user credentials to cause a denial-of-service condition. ...
Feb 11, 2026A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...
Feb 11, 2026A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...
Feb 11, 2026A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...
Feb 11, 2026CVE-2025-68699 is a NULL pointer dereference vulnerability in NanoMQ MQTT Broker that allows remote attackers to crash the broker by sending a malform...
Feb 4, 2026A vulnerability in TeamViewer DEX Client's Content Distribution Service (NomadBranch.exe) allows attackers on adjacent networks to crash the service v...
Jan 29, 2026ImageMagick versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL parser when processing <comment> tags before images ar...
Jan 22, 2026A NULL pointer dereference vulnerability in iccDEV library versions before 2.3.1.2 can cause application crashes or denial of service when processing ...
Jan 7, 2026This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...
Jan 6, 2026A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial-of-service conditions. This a...
Jan 2, 2026A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial-of-service conditions. This a...
Jan 2, 2026A NULL-pointer dereference vulnerability in Aqara smart home hubs allows attackers to cause denial-of-service by sending malformed JSON inputs. This a...
Dec 10, 2025Envoy proxy crashes when JWT authentication with remote JWKS fetching is configured, allow_missing_or_failed is enabled, multiple JWT tokens are prese...
Dec 3, 2025This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by having a ...
Dec 2, 2025This vulnerability allows attackers to cause a denial of service by sending a specially crafted ADTS audio file to Live555 Streaming Media servers. Th...
Dec 1, 2025A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated attackers to cause denial-of-service by crashing the service. Thi...
Nov 7, 2025A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated remote attackers to cause denial-of-service by crashing the servi...
Nov 7, 2025A NULL pointer dereference vulnerability in QNAP File Station allows authenticated attackers to cause denial-of-service conditions. This affects users...
Nov 7, 2025This vulnerability in Icinga 2 allows any authenticated API user to crash the monitoring daemon by creating invalid references (like null references) ...
Oct 16, 2025A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service by crashing the service. Th...
Oct 3, 2025A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects al...
Oct 3, 2025A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service conditions. This affects or...
Aug 29, 2025A NULL pointer dereference vulnerability in QNAP operating systems allows attackers to cause denial-of-service conditions by crashing affected systems...
Aug 29, 2025About NULL Pointer Dereference (CWE-476)
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Our database tracks 1,251 CVEs classified as CWE-476, with 20 rated critical and 303 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.
External reference: View CWE-476 on MITRE CWE →
Monitor NULL Pointer Dereference Vulnerabilities
Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.
Start Monitoring Free