CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,251
Total CVEs
20
Critical
303
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,251)

CVE-2025-30263
6.5

A NULL pointer dereference vulnerability in Qsync Central allows authenticated remote attackers to cause denial-of-service by crashing the service. Th...

Aug 29, 2025
CVE-2025-30267
6.5

A NULL pointer dereference vulnerability in QNAP operating systems allows authenticated remote attackers to cause denial-of-service conditions. This a...

Aug 29, 2025
CVE-2025-29886
6.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated remote attackers to cause denial-of-service by crashing the servi...

Aug 29, 2025
CVE-2025-29889
6.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated attackers to cause denial-of-service conditions. This affects use...

Aug 29, 2025
CVE-2025-29874
6.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated attackers to cause denial-of-service conditions. This affects use...

Aug 29, 2025
CVE-2025-29878
6.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated attackers to cause denial-of-service conditions. This affects use...

Aug 29, 2025
CVE-2025-29901
6.5

A NULL pointer dereference vulnerability in QNAP File Station 5 allows authenticated remote attackers to cause denial-of-service by crashing the servi...

Aug 26, 2025
CVE-2025-53716
6.5

A null pointer dereference vulnerability in Windows LSASS allows authenticated attackers to cause a denial of service by crashing the service. This af...

Aug 12, 2025
CVE-2025-24515
6.5

This CVE describes a NULL pointer dereference vulnerability in certain Intel Graphics Drivers that could allow an authenticated local user to cause a ...

Aug 12, 2025
CVE-2025-50952
6.5

This CVE describes a NULL pointer dereference vulnerability in openjpeg v2.5.0's DWT component that can cause denial of service. Attackers can crash a...

Aug 7, 2025
CVE-2025-49832
6.5

Asterisk has a vulnerability in its STIR/SHAKEN verification module that allows remote attackers to cause denial of service or potentially execute arb...

Aug 1, 2025
CVE-2025-30665
6.5

A NULL pointer dereference vulnerability in Zoom Workplace Apps for Windows allows authenticated users to cause a denial of service through network ac...

May 14, 2025
CVE-2025-30667
6.5

A NULL pointer dereference vulnerability in Zoom Workplace Apps for Windows allows authenticated users to cause denial of service through network acce...

May 14, 2025
CVE-2025-32910
6.5

A NULL pointer dereference vulnerability in libsoup's soup_auth_digest_authenticate() function can cause client applications to crash when processing ...

Apr 14, 2025
CVE-2025-30670
6.5

A null pointer dereference vulnerability in Zoom Workplace Apps for Windows allows authenticated users to cause denial of service through network acce...

Apr 8, 2025
CVE-2025-22921
6.5

This vulnerability in FFmpeg's JPEG2000 decoder allows attackers to cause a segmentation fault (crash) by processing specially crafted JPEG2000 images...

Feb 18, 2025
CVE-2024-57435
6.5

This vulnerability in macrozheng mall-tiny 1.0.1 allows attackers to cause denial-of-service by sending null data through the resource creation interf...

Jan 31, 2025
CVE-2024-57719
6.5

Lunasvg v3.0.0 contains a NULL pointer dereference vulnerability in the blend_transformed_tiled_argb.isra.0 component that can cause segmentation faul...

Jan 23, 2025
CVE-2023-37039
6.5

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sendi...

Jan 22, 2025
CVE-2024-24443
6.5

An uninitialized pointer dereference vulnerability in OpenAirInterface CN5G AMF allows attackers to cause Denial of Service (DoS) by sending a crafted...

Jan 21, 2025
CVE-2023-37037
6.5

This vulnerability allows network-adjacent attackers to crash the Mobile Management Entity (MME) in Magma cellular core networks by sending a malforme...

Jan 21, 2025
CVE-2023-37030
6.5

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sendi...

Jan 21, 2025
CVE-2023-37033
6.5

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sendi...

Jan 21, 2025
CVE-2023-37035
6.5

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sendi...

Jan 21, 2025
CVE-2023-37025
6.5

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sendi...

Jan 21, 2025
CVE-2023-37027
6.5

A null pointer dereference vulnerability in Magma's Mobile Management Entity (MME) allows network-adjacent attackers to crash the MME service by sendi...

Jan 21, 2025
CVE-2024-24445
6.5

OpenAirInterface CN5G AMF versions up to 2.0.0 contain a null pointer dereference vulnerability when processing unsupported NGAP protocol messages. An...

Jan 21, 2025
CVE-2023-42785
6.5

A null pointer dereference vulnerability in FortiOS allows attackers to cause denial of service via specially crafted HTTP requests. This affects Fort...

Jan 14, 2025
CVE-2024-36620
6.5

CVE-2024-36620 is a NULL pointer dereference vulnerability in Moby (Docker's open-source engine) that can cause a denial of service by crashing the Do...

Nov 29, 2024
CVE-2024-11706
6.5

A null pointer dereference vulnerability in pk12util's SEC_ASN1DecodeItem_Util function allows attackers to cause denial of service by crashing applic...

Nov 26, 2024
CVE-2024-24446
6.5

An uninitialized pointer dereference vulnerability in OpenAirInterface CN5G AMF allows attackers to cause Denial of Service (DoS) by sending a crafted...

Nov 15, 2024
CVE-2024-52296
6.5

This vulnerability in libosdp allows remote attackers to crash applications by sending specially crafted OSDP reply IDs. Any system using vulnerable v...

Nov 12, 2024
CVE-2024-10280
6.5

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argume...

Oct 23, 2024
CVE-2024-39132
6.5

A NULL pointer dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause denial of service by crashing the application. This affect...

Jun 27, 2024
CVE-2024-1914
6.5

This CVE describes a NULL pointer dereference vulnerability in ABB RobotWare that allows attackers to cause denial of service conditions. When exploit...

May 14, 2024
CVE-2024-27028
6.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's SPI-MT65xx driver interrupt handler. When the TX buffer in a spi_tra...

May 1, 2024
CVE-2021-47267
6.3

A NULL pointer dereference vulnerability in the Linux kernel USB gadget subsystem causes kernel panics when USB 3.1 (10Gbps) devices are connected to ...

May 21, 2024
CVE-2025-8090
6.2

A null pointer dereference vulnerability in the MsgRegisterEvent() system call in QNX Neutrino RTOS allows local attackers with code execution capabil...

Jan 13, 2026
CVE-2025-65835
6.2

This vulnerability allows any local Android application to repeatedly crash any app using the vulnerable cordova-plugin-x-socialsharing plugin by send...

Dec 15, 2025
CVE-2025-54409
6.2

AIDE versions 0.13 to 0.19.1 contain a null pointer dereference vulnerability that allows local attackers to crash the program by setting extended fil...

Aug 14, 2025
CVE-2025-31176
6.2

A NULL pointer dereference vulnerability in gnuplot's plot3d_points() function can cause segmentation faults leading to application crashes. This affe...

Mar 27, 2025
CVE-2025-31179
6.2

A NULL pointer dereference vulnerability in gnuplot's xstrftime() function can cause segmentation faults and application crashes when processing certa...

Mar 27, 2025
CVE-2025-31181
6.2

A NULL pointer dereference vulnerability in gnuplot's X11_graphics() function can cause segmentation faults and system crashes when processing malicio...

Mar 27, 2025
CVE-2024-39440
6.2

This CVE describes a null pointer dereference vulnerability in the DRM service that can cause system crashes. Attackers with local access and system e...

Oct 9, 2024
CVE-2024-23357
6.2

This vulnerability allows an attacker to cause a denial of service (DoS) by providing a specially crafted PKCS#8-encoded RSA key with a zero-byte modu...

Aug 5, 2024
CVE-2023-52861
6.2

A NULL pointer dereference vulnerability in the Linux kernel's IT66121 DisplayPort bridge driver allows local attackers to cause a kernel panic when n...

May 21, 2024
CVE-2023-52844
6.2

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's vidtv media driver PSI component. If kstrdup() fails to allocate mem...

May 21, 2024
CVE-2025-11187
6.1

This vulnerability in OpenSSL allows attackers to cause denial of service or potentially execute arbitrary code by crafting malicious PKCS#12 files th...

Jan 27, 2026
CVE-2026-24929
5.9

An out-of-bounds read vulnerability in the graphics module could allow attackers to read memory beyond allocated buffers, potentially causing applicat...

Feb 6, 2026
CVE-2025-15468
5.9

A NULL pointer dereference vulnerability in OpenSSL's SSL_CIPHER_find() function when used with QUIC protocol allows denial of service attacks. Applic...

Jan 27, 2026

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,251 CVEs classified as CWE-476, with 20 rated critical and 303 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free