CWE-476

Medium likelihood

NULL Pointer Dereference

Parent: CWE-710 - Improper Adherence to Coding Standards

The product dereferences a pointer that it expects to be valid but is NULL.

5,271 vulnerabilities with CWE-476
CVE-2025-14180 HIGH
PHP <8.1.34, <8.2.30, <8.3.29, <8.4.16, <8.5.1 - Buffer Overflow
CVSS 7.5
CVE-2025-14501 HIGH
Sante PACS Server - Unauthenticated Denial of Service via HTTP Content-Length Header Handling
CVSS 7.5
CVE-2025-14957 LOW
WebAssembly Binaryen < 125 - Null Pointer Dereference in IRBuilder Local Access Functions
CVSS 3.3
CVE-2025-14953 LOW
open5gs < 2.7.5 - Denial of Service via Null Pointer Dereference in FAR-ID Handler
CVSS 3.1
CVE-2025-65566 HIGH
omec-project UPF 2.1.3-dev - Denial of Service via Missing Cause IE in PFCP Session Report Response
CVSS 7.5
CVE-2025-65565 HIGH
omec-project UPF 2.1.3-dev - Denial of Service via Missing F-SEID in PFCP Session Establishment Request
CVSS 7.5
CVE-2025-65564 HIGH
omec-upf 2.1.3-dev - Denial of Service via Missing Recovery Time Stamp IE in PFCP Association Setup Request
CVSS 7.5
CVE-2025-65563 HIGH
omec-project UPF < 2.1.2 - Denial of Service via PFCP Association Setup Request
CVSS 7.5
CVE-2025-14841 LOW
OFFIS DCMTK <3.6.9 - Null Pointer Dereference
CVSS 3.3
CVE-2025-66646 HIGH
RIOT OS < 2025.10 - Denial of Service via IPv6 Fragmentation Reassembly NULL Pointer Dereference
CVSS 7.5
CVE-2025-68274 HIGH
emiago sipgo 0.3.0-1.0.0-alpha-1 - Denial of Service via NewResponseFromRequest Nil Pointer Dereference
CVSS 7.5
CVE-2025-62848 HIGH
QNAP QTS 5.2.x-5.2.7.3297 and QuTS hero h5.2.x-h5.2.7.3297 - Denial of Service via NULL Pointer Dereference
CVSS 7.5
CVE-2025-65835 MEDIUM
Cordova plugin-x-socialsharing 6.0.4 - Null Pointer
CVSS 6.2
CVE-2025-55314 HIGH
Foxit PDF & Editor <13.2-2025.2 - Memory Corruption
CVSS 7.8
CVE-2025-55312 HIGH
Foxit PDF & Editor <13.2-2025.2 - Memory Corruption
CVSS 7.8
CVE-2025-65296 MEDIUM
Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 - Denial of Service via JSON Processing
CVSS 6.5
CVE-2025-64086 HIGH
PDF-XChange Editor 10.7.3.401 - Denial of Service via util.readFileIntoStream NULL Pointer Dereference
CVSS 7.5
CVE-2025-64085 HIGH
PDF-XChange Editor 10.7.3.401 - Denial of Service via importDataObject() NULL Pointer Dereference
CVSS 7.5
CVE-2025-62466 HIGH
Microsoft Windows 10 1607 < 10.0.14393.8688 - NULL Pointer Dereference
CVSS 7.8
CVE-2025-62465 MEDIUM
Windows 11 22H2-25H2 and Windows Server 2022-2025 - Denial of Service via DirectX Null Pointer Dereference
CVSS 6.5
CVE-2025-62463 MEDIUM
Windows DirectX - Denial of Service via Null Pointer Dereference
CVSS 6.5
CVE-2025-14309 HIGH
Ravynsoft Ravynos <0.5.2 - NULL Pointer Dereference
CVSS 7.5
CVE-2025-6966 MEDIUM
python-apt - Denial of Service via Malformed Non-UTF-8 Key in TagSection.keys()
CVSS 5.5
CVE-2025-40251 MEDIUM
Linux Kernel 5.14-6.1.163, 6.2-6.6.117, 6.7-6.12.59, 6.13-6.17.9 - Use-After-Free in devlink Rate Node Destruction
CVSS 5.5
CVE-2025-64527 MEDIUM
Envoy <1.33.13, 1.34.10, 1.35.6, 1.36.2 - Denial of Service via JWT Authentication JWKS Fetch Re-entry Bug
CVSS 6.5
Details
Vulnerabilities 5,271
Exploit Likelihood Medium