CWE-476

Medium likelihood

NULL Pointer Dereference

Parent: CWE-710 - Improper Adherence to Coding Standards

The product dereferences a pointer that it expects to be valid but is NULL.

5,459 vulnerabilities with CWE-476
CVE-2026-9759 MEDIUM
NULL Pointer Dereference in Wireshark
CVSS 5.5
CVE-2026-8360 HIGH
Gladinet Triofox Unchecked Return Value to NULL Pointer Dereference DOS
CVSS 7.5
CVE-2026-8359 HIGH
Gladinet Triofox WOSHttpStatusModule.dll NULL Function Pointer Call DoS
CVSS 7.5
CVE-2026-48066 MEDIUM
pam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authentication
CVSS 5.7
CVE-2026-47271 MEDIUM
pam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentication process crash
CVSS 5.1
CVE-2026-45104 HIGH
MapServer: NULL pointer dereference in SLD `<ElseFilter>` rule parsing reachable via WMS `SLD_BODY`
CVSS 7.5
CVE-2026-44328 HIGH
free5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating
CVSS 8.2
CVE-2026-44323 MEDIUM
free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)
CVSS 4.3
CVE-2026-44322 HIGH
free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
CVSS 7.5
CVE-2026-44317 MEDIUM
free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference
CVSS 6.5
CVE-2026-44316 HIGH
free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference
CVSS 7.5
CVE-2026-8180 HIGH
IBM Aspera High-Speed Transfer Endpoint - Multiple Vulnerabilities in Aspera applications.
CVSS 7.5
CVE-2026-46098 MEDIUM
net: caif: clear client service pointer on teardown
CVSS 5.5
CVE-2026-46092 MEDIUM
wifi: rtw88: check for PCI upstream bridge existence
CVSS 5.5
CVE-2026-46086 MEDIUM
net: bridge: use a stable FDB dst snapshot in RCU readers
CVSS 5.5
CVE-2026-46079 MEDIUM
rbd: fix null-ptr-deref when device_add_disk() fails
CVSS 5.5
CVE-2026-46034 MEDIUM
vfio/cdx: Fix NULL pointer dereference in interrupt trigger path
CVSS 5.5
CVE-2026-46024 HIGH
libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()
CVSS 7.5
CVE-2026-46016 MEDIUM
remoteproc: xlnx: Only access buffer information if IPI is buffered
CVSS 5.5
CVE-2026-45982 MEDIUM
ACPICA: Fix NULL pointer dereference in acpi_ev_address_space_dispatch()
CVSS 5.5
CVE-2026-45978 MEDIUM
staging: greybus: lights: avoid NULL deref
CVSS 5.5
CVE-2026-45969 MEDIUM
HID: playstation: Add missing check for input_ff_create_memless
CVSS 5.5
CVE-2026-45968 MEDIUM
cpuidle: Skip governor when only one idle state is available
CVSS 5.5
CVE-2026-45966 MEDIUM
apparmor: fix NULL pointer dereference in __unix_needs_revalidation
CVSS 5.5
CVE-2026-45965 MEDIUM
apparmor: fix invalid deref of rawdata when export_binary is unset
CVSS 5.5
Details
Vulnerabilities 5,459
Exploit Likelihood Medium