CWE-476

Medium likelihood

NULL Pointer Dereference

Parent: CWE-710 - Improper Adherence to Coding Standards

The product dereferences a pointer that it expects to be valid but is NULL.

5,459 vulnerabilities with CWE-476
CVE-2026-41069 MEDIUM
libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)
CVSS 6.5
CVE-2026-39835 MEDIUM
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
CVSS 5.3
CVE-2026-43496 MEDIUM
net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
CVSS 5.5
CVE-2026-32738 MEDIUM
libheif <1.22.0 samples_per_chunk - Out-of-Bounds Read Denial of Service
CVSS 6.5
CVE-2026-32134 MEDIUM
NanoMQ: NULL Pointer Dereference Crash in tcptran_pipe_peer During Session Restore
CVSS 5.9
CVE-2026-47308 MEDIUM
Samsung Open Source Walrus f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9 - NULL Pointer Dereference
CVSS 5.5
CVE-2026-47307 MEDIUM
Samsung Open Source Walrus f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9 - Denial of Service via Crafted WebAssembly Module
CVSS 5.5
CVE-2026-25110 LOW
OpenHarmony <=6.0 sensors_medical_sensor - NULL Pointer Dereference Denial of Service
CVSS 3.3
CVE-2026-32849 MEDIUM
NetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c
CVSS 5.5
CVE-2026-8783 MEDIUM
omec-project amf dispatcher.go UERadioCapabilityCheckResponse null pointer dereference
CVSS 4.3
CVE-2026-8782 MEDIUM
omec-project amf NGAP Message handler.go null pointer dereference
CVSS 4.3
CVE-2026-8781 MEDIUM
omec-project amf handler.go RANConfiguration null pointer dereference
CVSS 4.3
CVE-2026-8723 MEDIUM
qs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly
CVSS 5.3
CVE-2026-44638 LOW
libsixel: NULL pointer dereference
CVSS 2.5
CVE-2026-43480 MEDIUM
ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition
CVSS 5.5
CVE-2026-42409 HIGH
F5 BIG-IP HTTP/2 iRule - TMM Denial of Service
CVSS 7.5
CVE-2026-42442 LOW
NanaZip: Null-pointer dereference in NanaZip UFS parser when root inode is a symlink
CVSS 3.3
CVE-2026-40414 HIGH
Microsoft Windows TCP/IP - Adjacent-Network Null Pointer Denial of Service
CVSS 7.4
CVE-2026-40413 HIGH
Microsoft Windows TCP/IP - Adjacent-Network Null Pointer Denial of Service
CVSS 7.4
CVE-2026-40405 HIGH
Microsoft Windows TCP/IP - Null Pointer Denial of Service
CVSS 7.5
CVE-2026-40401 HIGH
Microsoft Windows TCP/IP - Local Null Pointer Denial of Service
CVSS 7.1
CVE-2026-34662 MEDIUM
Illustrator | NULL Pointer Dereference (CWE-476)
CVSS 5.5
CVE-2026-34350 MEDIUM
Microsoft Windows Server 2025 - Windows Storport Miniport Driver Denial of Service Vulnerability
CVSS 6.5
CVE-2026-34339 MEDIUM
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVSS 5.5
CVE-2026-20914 MEDIUM
Intel(R) QAT software drivers for Windows < 2.6.0 - Denial of Service via Null Pointer Dereference
CVSS 5.5
Details
Vulnerabilities 5,459
Exploit Likelihood Medium