CWE-476
Medium likelihoodNULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
5,459 vulnerabilities with CWE-476
CVE-2026-18064
HIGH
NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference
CVSS 7.5
CVE-2026-58161
HIGH
Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server
CVSS 7.5
CVE-2026-67184
HIGH
TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
CVSS 7.5
CVE-2026-66749
MEDIUM
Let's Chat 0.4.0-0.4.8 - Authenticated Room Lookup Denial of Service
CVSS 6.5
CVE-2026-47427
HIGH
GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler
CVSS 7.5
CVE-2026-17574
MEDIUM
NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag
CVE-2026-17500
MEDIUM
ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference
CVSS 5.3
CVE-2026-45816
HIGH
Apache NimBLE <= 1.9.0 SMP LTK Request - NULL Pointer Dereference
CVSS 7.5
CVE-2026-50032
HIGH
NULL Pointer Dereference in MZ Automation libIEC61850
CVSS 7.5
CVE-2026-13070
MEDIUM
Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Termination
CVSS 5.3
CVE-2026-13065
MEDIUM
MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination
CVSS 6.5
CVE-2026-55717
MEDIUM
'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
CVSS 5.9
CVE-2026-47709
MEDIUM
libheif has a NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe
CVSS 5.5
CVE-2026-10678
HIGH
NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller
CVSS 8.1
CVE-2026-47143
MEDIUM
Capstone has a NULL Pointer Dereference with 3DNow! opcodes
CVSS 5.1
CVE-2026-16353
CRITICAL
Invalid pointer in the DOM: Bindings (WebIDL) component
CVSS 9.8
CVE-2026-47276
MEDIUM
NULL Pointer Dereference in REST API properties_parse via Malformed user_properties
CVSS 6.5
CVE-2026-47275
LOW
nanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to Remote DoS
CVSS 2.6
CVE-2026-63762
MEDIUM
SurrealDB before v2.6.1 Denial of Service via scripting
CVSS 6.5
CVE-2026-53403
MEDIUM
fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
CVSS 5.5
CVE-2026-53399
CRITICAL
nfsd: release layout stid on setlease failure
CVSS 9.8
CVE-2026-53392
HIGH
NFSv4/flexfiles: reject zero filehandle version count
CVSS 7.5
CVE-2026-53391
HIGH
NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
CVSS 7.5
CVE-2026-53385
MEDIUM
vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
CVSS 5.5
CVE-2026-53383
HIGH
ksmbd: reject non-VALID session in compound request branch
CVSS 7.5
Details
Vulnerabilities
5,459
Exploit Likelihood
Medium