CWE-476

Medium likelihood

NULL Pointer Dereference

Parent: CWE-710 - Improper Adherence to Coding Standards

The product dereferences a pointer that it expects to be valid but is NULL.

5,257 vulnerabilities with CWE-476
CVE-2026-10199 LOW
Assimp glTF2Asset.h LazyDict null pointer dereference
CVSS 3.3
CVE-2026-10198 LOW
Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference
CVSS 3.3
CVE-2026-10197 LOW
Assimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference
CVSS 3.3
CVE-2026-46527 HIGH
cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server Crash
CVSS 7.5
CVE-2026-45151 LOW
NanoMQ: NULL Pointer Dereference
CVE-2026-47337 LOW
NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation
CVSS 3.3
CVE-2026-47335 MEDIUM
NULL pointer dereference in Ubuntu Linux AppArmor notification handling
CVSS 5.5
CVE-2026-47327 LOW
NULL pointer dereference in Ubuntu Linux AppArmor notification handling
CVSS 3.3
CVE-2026-46235 MEDIUM
media: saa7164: add ioremap return checks and cleanups
CVSS 5.5
CVE-2026-46233 MEDIUM
batman-adv: bla: only purge non-released claims
CVSS 5.5
CVE-2026-46222 MEDIUM
media: rockchip: rkcif: Add missing MUST_CONNECT flag to pads
CVSS 5.5
CVE-2026-46216 MEDIUM
drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status()
CVSS 5.5
CVE-2026-46211 MEDIUM
drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata()
CVSS 5.5
CVE-2026-46195 CRITICAL
smb: client: validate dacloffset before building DACL pointers
CVSS 9.8
CVE-2026-46188 MEDIUM
octeon_ep_vf: add NULL check for napi_build_skb()
CVSS 5.5
CVE-2026-44710 MEDIUM
pam_usb: NULL pointer dereference from UDisks device fields causes PAM crash and login denial-of-service
CVSS 4.6
CVE-2026-9759 MEDIUM
NULL Pointer Dereference in Wireshark
CVSS 5.5
CVE-2026-8360 HIGH
Gladinet Triofox Unchecked Return Value to NULL Pointer Dereference DOS
CVSS 7.5
CVE-2026-8359 HIGH
Gladinet Triofox WOSHttpStatusModule.dll NULL Function Pointer Call DoS
CVSS 7.5
CVE-2026-48066 MEDIUM
pam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authentication
CVSS 5.7
CVE-2026-47271 MEDIUM
pam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentication process crash
CVSS 5.1
CVE-2026-45104 HIGH
MapServer: NULL pointer dereference in SLD `<ElseFilter>` rule parsing reachable via WMS `SLD_BODY`
CVSS 7.5
CVE-2026-44328 HIGH
free5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating
CVSS 8.2
CVE-2026-44323 MEDIUM
free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)
CVSS 4.3
CVE-2026-44322 HIGH
free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
CVSS 7.5
Details
Vulnerabilities 5,257
Exploit Likelihood Medium