CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,251
Total CVEs
20
Critical
303
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,251)

CVE-2024-3184
5.9

This vulnerability allows remote attackers to cause denial of service (DoS) by crashing GoAhead Web Server through NULL pointer dereference. It affect...

Oct 17, 2024
CVE-2023-28827
5.9

A denial-of-service vulnerability in Siemens SIMATIC industrial communication processors and related products allows remote attackers to crash devices...

Sep 10, 2024
CVE-2025-24179
5.7

This CVE describes a null pointer dereference vulnerability in multiple Apple operating systems that was fixed with improved input validation. An atta...

Apr 29, 2025
CVE-2025-47808
5.6

A NULL pointer dereference vulnerability in GStreamer's subparse plugin can cause application crashes when processing malicious subtitle files. This a...

Aug 7, 2025
CVE-2026-21350
5.5

Adobe After Effects versions 25.6 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by trick...

Feb 10, 2026
CVE-2026-21338
5.5

Substance3D Designer versions 15.1.0 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by tr...

Feb 10, 2026
CVE-2025-33237
5.5

The NVIDIA HD Audio Driver for Windows contains a NULL pointer dereference vulnerability that could allow an attacker to cause a denial of service (sy...

Jan 28, 2026
CVE-2026-22998
5.5

A NULL pointer dereference vulnerability in the Linux kernel's NVMe over TCP implementation allows attackers to cause kernel panics and system crashes...

Jan 25, 2026
CVE-2026-22996
5.5

A use-after-free vulnerability in the Linux kernel's mlx5e network driver causes a kernel NULL pointer dereference when switchdev mode fails during pr...

Jan 25, 2026
CVE-2026-23000
5.5

A race condition vulnerability in the Linux kernel's mlx5e network driver causes a NULL pointer dereference when changing network profiles fails and l...

Jan 25, 2026
CVE-2026-22991
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's libceph component. If exploited, it could cause a kernel panic leadi...

Jan 23, 2026
CVE-2026-22992
5.5

A Linux kernel vulnerability in the libceph component where authentication errors aren't properly propagated, causing msgr2 to continue establishing s...

Jan 23, 2026
CVE-2026-22993
5.5

A NULL pointer dereference vulnerability in the Linux kernel's idpf driver allows local attackers to cause a kernel panic (denial of service) by acces...

Jan 23, 2026
CVE-2026-22981
5.5

A race condition vulnerability in the Linux kernel's idpf driver allows simultaneous hard and soft resets to cause network interfaces to lose state or...

Jan 23, 2026
CVE-2026-22982
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ocelot network driver causes a kernel crash when adding a network interface under a lin...

Jan 23, 2026
CVE-2026-22983
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's net subsystem, specifically in the af_unix socket implementation. Th...

Jan 23, 2026
CVE-2026-22985
5.5

A NULL pointer dereference vulnerability in the Linux kernel's idpf driver causes a kernel crash when ethtool operations (like rxhash on/off) are perf...

Jan 23, 2026
CVE-2026-22987
5.5

A Linux kernel vulnerability in the net/sched traffic control subsystem where error pointers are incorrectly dereferenced during network namespace tea...

Jan 23, 2026
CVE-2026-22977
5.5

This CVE describes a kernel panic vulnerability in the Linux kernel's networking subsystem when CONFIG_HARDENED_USERCOPY is enabled. The vulnerability...

Jan 21, 2026
CVE-2026-22976
5.5

A NULL pointer dereference vulnerability in the Linux kernel's QFQ (Quick Fair Queueing) scheduler allows local attackers to cause a kernel panic and ...

Jan 21, 2026
CVE-2025-60007
5.5

A local attacker with low privileges can cause a denial-of-service on Juniper Junos OS devices by executing a specially crafted 'show chassis' command...

Jan 15, 2026
CVE-2026-21288
5.5

Adobe Illustrator versions 29.8.3, 30.0 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application by...

Jan 13, 2026
CVE-2023-54321
5.5

A null pointer dereference vulnerability in the Linux kernel's device_add() function can cause kernel crashes when device registration fails during fa...

Dec 30, 2025
CVE-2025-6966
5.5

A NULL pointer dereference vulnerability in python-apt's TagSection.keys() function allows local attackers to crash processes by providing malformed d...

Dec 5, 2025
CVE-2025-40251
5.5

A Linux kernel vulnerability in the devlink rate subsystem leaves dangling parent pointers when destroying rate objects, causing memory corruption and...

Dec 4, 2025
CVE-2025-63745
5.5

A NULL pointer dereference vulnerability in radare2 versions 6.0.5 and earlier allows attackers to cause a denial of service via a segmentation fault....

Nov 14, 2025
CVE-2025-26694
5.5

A null pointer dereference vulnerability in Intel QAT Windows software before version 2.6.0 allows authenticated local users to cause denial of servic...

Nov 11, 2025
CVE-2025-23330
5.5

NVIDIA Display Driver for Linux contains a null pointer dereference vulnerability that could allow an attacker to cause a denial of service. This affe...

Oct 23, 2025
CVE-2025-54270
5.5

Adobe Animate versions 23.0.13, 24.0.10 and earlier contain a NULL pointer dereference vulnerability that could allow memory exposure when processing ...

Oct 15, 2025
CVE-2025-39959
5.5

This CVE describes a null pointer dereference vulnerability in the AMD ACP I2S driver of the Linux kernel. The vulnerability occurs when the driver in...

Oct 9, 2025
CVE-2023-53686
5.5

A null pointer dereference vulnerability in the Linux kernel's handshake netlink subsystem allows local attackers to cause a kernel panic (denial of s...

Oct 7, 2025
CVE-2023-53678
5.5

This CVE-2023-53678 is a NULL pointer dereference vulnerability in the Linux kernel's Intel i915 graphics driver. It occurs when attempting to suspend...

Oct 7, 2025
CVE-2023-53664
5.5

This CVE-2023-53664 is a null pointer dereference vulnerability in the Linux kernel's OPP (Operating Performance Points) framework. It occurs when the...

Oct 7, 2025
CVE-2023-53667
5.5

A kernel memory corruption vulnerability in the Linux kernel's CDC NCM USB network driver allows for potential denial-of-service attacks when handling...

Oct 7, 2025
CVE-2023-53657
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's ice network driver. An attacker could potentially cause a kernel pan...

Oct 7, 2025
CVE-2023-53647
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Hyper-V VMBus driver allows local attackers to cause a kernel panic (system crash) by t...

Oct 7, 2025
CVE-2023-53648
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's AC97 audio driver. If exploited, it could cause a kernel panic leadi...

Oct 7, 2025
CVE-2023-53625
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Intel GVT (Graphics Virtualization Technology) driver. When removing...

Oct 7, 2025
CVE-2023-53627
5.5

This CVE describes a race condition vulnerability in the Linux kernel's HiSilicon SAS controller driver (hisi_sas) where concurrent access to the sas_...

Oct 7, 2025
CVE-2022-50555
5.5

A null pointer dereference vulnerability in the Linux kernel's TIPC (Transparent Inter-Process Communication) subsystem allows local denial of service...

Oct 7, 2025
CVE-2022-50538
5.5

This CVE-2022-50538 is a Linux kernel vulnerability in the VME subsystem where the fake_init() function fails to properly handle errors from __root_de...

Oct 7, 2025
CVE-2022-50535
5.5

This CVE describes a null pointer dereference vulnerability in the AMD display driver within the Linux kernel. If exploited, it could cause a kernel p...

Oct 7, 2025
CVE-2022-50530
5.5

A NULL pointer dereference vulnerability in the Linux kernel's block multi-queue subsystem allows local attackers to trigger a kernel panic (denial of...

Oct 7, 2025
CVE-2022-50533
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's WiFi subsystem (mac80211). When a device fails to associate with an ...

Oct 7, 2025
CVE-2022-50524
5.5

A null pointer dereference vulnerability in the MediaTek IOMMU driver of the Linux kernel could cause kernel panic or system crash when platform_get_r...

Oct 7, 2025
CVE-2022-50527
5.5

This CVE-2022-50527 is a NULL pointer dereference vulnerability in the AMD GPU driver within the Linux kernel. It allows local attackers to cause a ke...

Oct 7, 2025
CVE-2022-50516
5.5

This vulnerability in the Linux kernel's Distributed Lock Manager (DLM) component allows a NULL pointer dereference when unlocking locks without the D...

Oct 7, 2025
CVE-2022-50509
5.5

This CVE is a NULL pointer dereference vulnerability in the Linux kernel's CODA media driver. If exploited, it could cause a kernel panic leading to d...

Oct 7, 2025
CVE-2023-53612
5.5

A NULL pointer dereference vulnerability in the Linux kernel's coretemp hardware monitoring driver could cause kernel panics or system crashes when CP...

Oct 4, 2025
CVE-2023-53603
5.5

This CVE describes a NULL pointer dereference vulnerability in the qla2xxx SCSI driver in the Linux kernel. If exploited, it could cause a kernel pani...

Oct 4, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,251 CVEs classified as CWE-476, with 20 rated critical and 303 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free