CWE-476

Medium likelihood

NULL Pointer Dereference

Parent: CWE-710 - Improper Adherence to Coding Standards

The product dereferences a pointer that it expects to be valid but is NULL.

5,266 vulnerabilities with CWE-476
CVE-2026-23249 MEDIUM
xfs: check for deleted cursors when revalidating two btrees
CVSS 5.5
CVE-2026-23242 HIGH
RDMA/siw: Fix potential NULL pointer dereference in header processing
CVSS 7.5
CVE-2026-32778 LOW
libexpat < 2.7.5 - NULL Pointer Dereference in setContext Function
CVSS 2.9
CVE-2026-32776 MEDIUM
libexpat < 2.7.5 - NULL Pointer Dereference via Empty External Parameter Entity
CVSS 4.0
CVE-2026-28522 MEDIUM
arduino-TuyaOpen WiFiUDP Null Pointer Dereference Denial of Service
CVSS 6.5
CVE-2026-32249 MEDIUM
Vim 9.1.0011-9.2.0137 - Memory Corruption
CVSS 5.3
CVE-2026-27218 MEDIUM
Substance 3D Painter < 11.1.3 - Denial of Service via NULL Pointer Dereference
CVSS 5.5
CVE-2026-27217 MEDIUM
Substance 3D Painter < 11.1.3 - Denial of Service via Malicious File
CVSS 5.5
CVE-2026-27215 MEDIUM
Substance 3D Painter < 11.1.3 - Denial of Service via Malicious File
CVSS 5.5
CVE-2026-27214 MEDIUM
Substance 3D Painter < 11.1.3 - Denial of Service via Malicious File
CVSS 5.5
CVE-2026-21364 MEDIUM
Substance 3D Painter < 11.1.3 - Denial of Service via NULL Pointer Dereference
CVSS 5.5
CVE-2026-21363 MEDIUM
Substance 3D Painter < 11.1.3 - Denial of Service via Malicious File
CVSS 5.5
CVE-2026-31792 HIGH
iccdev < 2.3.1.5 - Denial of Service via Null Pointer Dereference in CIccTagXmlStruct::ParseTag()
CVSS 7.8
CVE-2026-30986 MEDIUM
iccDEV <2.3.1.5 - Memory Corruption
CVSS 5.5
CVE-2026-25168 MEDIUM
Windows 10/11 DoS via Null Pointer Dereference
CVSS 6.2
CVE-2026-25165 HIGH
Windows Performance Counters - Privilege Escalation
CVSS 7.8
CVE-2026-24641 LOW
FortiWeb 7.0.0-7.6.6, 8.0.0-8.0.2 - Authenticated Denial of Service via HTTP Request
CVSS 2.7
CVE-2026-24293 HIGH
Windows AFD for WinSock - Privilege Escalation
CVSS 7.8
CVE-2026-3665 LOW
xlnt-community xlnt <=1.6.1 - Memory Corruption
CVSS 3.3
CVE-2026-29781 MEDIUM
Sliver <= 1.7.3 - Authenticated Denial of Service via Protobuf Unmarshalling
CVSS 6.5
CVE-2026-20064 MEDIUM
Cisco Secure Firewall Threat Defense Software - Authenticated Denial of Service via CLI Command Injection
CVSS 6.5
CVE-2026-23237 MEDIUM
Linux Kernel - NULL Pointer Dereference
CVSS 5.5
CVE-2026-3408 MEDIUM
Open Babel <=3.1.1 - Memory Corruption
CVSS 4.3
CVE-2026-3392 LOW
FascinatedBox lily <=2.3 - Memory Corruption
CVSS 3.3
CVE-2026-3389 LOW
Squirrel up to 3.2 - Memory Corruption
CVSS 3.3
Details
Vulnerabilities 5,266
Exploit Likelihood Medium