CWE-476

Medium likelihood

NULL Pointer Dereference

Parent: CWE-710 - Improper Adherence to Coding Standards

The product dereferences a pointer that it expects to be valid but is NULL.

5,266 vulnerabilities with CWE-476
CVE-2026-53463 MEDIUM
ImageMagick: Null Pointer Dereference in distort operation when passing incorrect arguments
CVSS 4.3
CVE-2026-24716 HIGH
QNAP Systems - QTS, QuTS Hero
CVSS 7.2
CVE-2026-22899 MEDIUM
Qnap Systems Inc. File Station 5 < 5.5.6.5208 - Denial of Service
CVSS 6.5
CVE-2026-45541 HIGH
Espressif ESP-IDF WebSocket Server - NULL Pointer Dereference
CVSS 7.5
CVE-2026-9752 MEDIUM
GeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generation
CVSS 6.5
CVE-2026-9743 MEDIUM
MongoDB Server 8.0 - Authenticated getMore Denial of Service
CVSS 6.5
CVE-2026-34704 MEDIUM
InDesign Desktop | NULL Pointer Dereference (CWE-476)
CVSS 5.5
CVE-2026-34703 MEDIUM
InDesign Desktop | NULL Pointer Dereference (CWE-476)
CVSS 5.5
CVE-2026-42903 MEDIUM
Microsoft Windows 10 Version 1607 - Windows Kerberos Denial of Service Vulnerability
CVSS 6.5
CVE-2026-42767 MEDIUM
OpenSSL - NULL Pointer Dereference in CRMF EncryptedValue Decryption
CVSS 5.9
CVE-2026-42766 MEDIUM
OpenSSL - Possible NULL Dereference in Password-Based CMS Decryption
CVSS 5.9
CVE-2026-42765 HIGH
OpenSSL - NULL Dereference in Certificate Verification with OCSP Checking
CVSS 7.5
CVE-2026-42764 HIGH
NULL Pointer Dereference in QUIC Server Initial Packet Handling
CVSS 7.5
CVE-2026-11788 MEDIUM
389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser
CVSS 5.9
CVE-2026-3238 HIGH
Samba: denial of service against ad dc wins server
CVSS 7.5
CVE-2026-46269 MEDIUM
pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree
CVSS 5.5
CVE-2026-46261 MEDIUM
spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe()
CVSS 5.5
CVE-2026-46258 MEDIUM
gpio: cdev: Avoid NULL dereference in linehandle_create()
CVSS 5.5
CVE-2026-46245 MEDIUM
drm/amd/display: Fix dc_link NULL handling in HPD init
CVSS 5.5
CVE-2026-8035 HIGH
NI-PAL Through 26.3.0 - Kernel Driver NULL Pointer Denial of Service
CVSS 7.1
CVE-2026-10298 LOW
whisper.cpp <= 1.8.2 - Null Pointer Dereference in whisper_model_load
CVSS 3.3
CVE-2026-28581 MEDIUM
Android 15-16 CallIntentProcessor - Emergency Call Logic Error
CVSS 4.0
CVE-2026-45729 MEDIUM
Thor Vector Graphics < 1.0.5 - Denial of Service via Null Pointer Dereference in SvgLoader
CVSS 4.3
CVE-2026-37230 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via Invalid ran_func_id in RIC_INDICATION
CVSS 7.5
CVE-2026-37226 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via E42_RIC_SUBSCRIPTION_REQUEST
CVSS 7.5
Details
Vulnerabilities 5,266
Exploit Likelihood Medium