CWE-476

Medium likelihood

NULL Pointer Dereference

Parent: CWE-710 - Improper Adherence to Coding Standards

The product dereferences a pointer that it expects to be valid but is NULL.

5,028 vulnerabilities with CWE-476
CVE-2026-23439 MEDIUM
udp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n
CVSS 5.5
CVE-2026-23438 MEDIUM
net: mvpp2: guard flow control update with global_tx_fc in buffer switching
CVSS 5.5
CVE-2026-23435 MEDIUM
perf/x86: Move event pointer setup earlier in x86_pmu_enable()
CVSS 5.5
CVE-2026-23433 MEDIUM
arm_mpam: Fix null pointer dereference when restoring bandwidth counters
CVSS 5.5
CVE-2026-34761 MEDIUM
Ella Core Panics Upon NGAP handover failure
CVSS 5.8
CVE-2026-31931 HIGH
Suricata tls: null dereference in tls.alpn rule keyword
CVSS 7.5
CVE-2026-34874 HIGH
Mbed TLS <3.6.5/4.0.0 - DoS
CVSS 7.5
CVE-2026-3776 MEDIUM
Null pointer dereference in Foxit PDF Editor/Reader when accessing stamp annotation
CVSS 5.5
CVE-2026-34552 MEDIUM
iccDEV: UB at IccTagLut.cpp
CVSS 6.2
CVE-2026-34551 MEDIUM
iccDEV: NPD in CIccTagLut16::Write()
CVSS 6.2
CVE-2026-34541 MEDIUM
iccDEV: UB in CIccCombinedConnectionConditions::CIccCombinedConnectionConditions()
CVSS 6.2
CVE-2026-32696 LOW
NanoMQ HTTP Auth: Missing username/password can trigger a NULL-pointer strlen() in auth_http.c:set_data(), causing a process crash — SIGSEGV, remotely triggerable
CVSS 3.1
CVE-2026-33996 MEDIUM
LibJWT has NULL/bounds validation in JWK octet and RSA PSS parsing
CVSS 5.5
CVE-2026-33907 MEDIUM
Ella Core Panics during NAS Authentication Response/Failure with missing IEs
CVSS 6.5
CVE-2026-33903 MEDIUM
Ella Core panics when processing a crafted NGAP LocationReport message
CVSS 6.5
CVE-2026-0968 LOW
Libssh: libssh: denial of service due to malformed sftp message
CVSS 3.1
CVE-2026-4652 HIGH
Freebsd < p5 - Denial of Service
CVSS 7.5
CVE-2026-29785 HIGH
NATS Server panic via malicious compression on leafnode port
CVSS 7.5
CVE-2026-23382 MEDIUM
HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them
CVSS 5.5
CVE-2026-23381 MEDIUM
net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled
CVSS 5.5
CVE-2026-23366 MEDIUM
drm/client: Do not destroy NULL modes
CVSS 5.5
CVE-2026-23349 MEDIUM
HID: pidff: Fix condition effect bit clearing
CVSS 5.5
CVE-2026-23341 MEDIUM
accel/amdxdna: Fix crash when destroying a suspended hardware context
CVSS 5.5
CVE-2026-23332 MEDIUM
cpufreq: intel_pstate: Fix crash during turbo disable
CVSS 5.5
CVE-2026-23328 MEDIUM
accel/amdxdna: Fix NULL pointer dereference of mgmt_chann
CVSS 5.5
Details
Vulnerabilities 5,028
Exploit Likelihood Medium