CWE-476
Medium likelihoodNULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
5,459 vulnerabilities with CWE-476
CVE-2026-41069
MEDIUM
libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)
CVSS 6.5
CVE-2026-39835
MEDIUM
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
CVSS 5.3
CVE-2026-43496
MEDIUM
net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
CVSS 5.5
CVE-2026-32738
MEDIUM
libheif <1.22.0 samples_per_chunk - Out-of-Bounds Read Denial of Service
CVSS 6.5
CVE-2026-32134
MEDIUM
NanoMQ: NULL Pointer Dereference Crash in tcptran_pipe_peer During Session Restore
CVSS 5.9
CVE-2026-47308
MEDIUM
Samsung Open Source Walrus f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9 - NULL Pointer Dereference
CVSS 5.5
CVE-2026-47307
MEDIUM
Samsung Open Source Walrus f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9 - Denial of Service via Crafted WebAssembly Module
CVSS 5.5
CVE-2026-25110
LOW
OpenHarmony <=6.0 sensors_medical_sensor - NULL Pointer Dereference Denial of Service
CVSS 3.3
CVE-2026-32849
MEDIUM
NetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c
CVSS 5.5
CVE-2026-8783
MEDIUM
omec-project amf dispatcher.go UERadioCapabilityCheckResponse null pointer dereference
CVSS 4.3
CVE-2026-8782
MEDIUM
omec-project amf NGAP Message handler.go null pointer dereference
CVSS 4.3
CVE-2026-8781
MEDIUM
omec-project amf handler.go RANConfiguration null pointer dereference
CVSS 4.3
CVE-2026-8723
MEDIUM
qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly
CVSS 5.3
CVE-2026-44638
LOW
libsixel: NULL pointer dereference
CVSS 2.5
CVE-2026-43480
MEDIUM
ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition
CVSS 5.5
CVE-2026-42409
HIGH
F5 BIG-IP HTTP/2 iRule - TMM Denial of Service
CVSS 7.5
CVE-2026-42442
LOW
NanaZip: Null-pointer dereference in NanaZip UFS parser when root inode is a symlink
CVSS 3.3
CVE-2026-40414
HIGH
Microsoft Windows TCP/IP - Adjacent-Network Null Pointer Denial of Service
CVSS 7.4
CVE-2026-40413
HIGH
Microsoft Windows TCP/IP - Adjacent-Network Null Pointer Denial of Service
CVSS 7.4
CVE-2026-40405
HIGH
Microsoft Windows TCP/IP - Null Pointer Denial of Service
CVSS 7.5
CVE-2026-40401
HIGH
Microsoft Windows TCP/IP - Local Null Pointer Denial of Service
CVSS 7.1
CVE-2026-34662
MEDIUM
Illustrator | NULL Pointer Dereference (CWE-476)
CVSS 5.5
CVE-2026-34350
MEDIUM
Microsoft Windows Server 2025 - Windows Storport Miniport Driver Denial of Service Vulnerability
CVSS 6.5
CVE-2026-34339
MEDIUM
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVSS 5.5
CVE-2026-20914
MEDIUM
Intel(R) QAT software drivers for Windows < 2.6.0 - Denial of Service via Null Pointer Dereference
CVSS 5.5
Details
Vulnerabilities
5,459
Exploit Likelihood
Medium