← Back to feed Search feed

CWE-476 NULL Pointer Dereference vulnerabilities

137 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-55209resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata iCRITICAL9.836%ileNVD2026-09-14
CVE-2026-93107In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Avoid reprocessing the current packet aftHIGH8.210%ileNVD2026-09-17
CVE-2026-90207In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: midi: Serialize input teardown with evenHIGH7.811%ileNVD2026-09-17
CVE-2026-89511In the Linux kernel, the following vulnerability has been resolved: qede: Fix NULL pointer dereference in TPA fragment HIGH7.552%ileNVD2026-09-11
CVE-2026-89528In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Read lists that exceed the page budHIGH7.549%ileNVD2026-09-11
CVE-2026-89696In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to pHIGH7.554%ileNVD2026-09-11
CVE-2026-15891The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record afterHIGH7.527%ileNVD2026-09-13
CVE-2026-77692An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(HIGH7.540%ileNVD2026-09-16
CVE-2026-92626Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintHIGH7.530%ileNVD2026-09-16
CVE-2026-90228In the Linux kernel, the following vulnerability has been resolved: nvmet: fix NULL pointer dereference in nvmet_executHIGH7.511%ileNVD2026-09-17
CVE-2026-55204HAProxy - NULL Pointer Dereference in hpack_dht_insert FunctionHIGH7.541%ileMicrosoft2026-06-09
CVE-2026-57434Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classesHIGH7.539%ileMicrosoft2026-06-09
CVE-2026-42764NULL Pointer Dereference in QUIC Server Initial Packet HandlingHIGH7.566%ileMicrosoft2026-06-09
CVE-2026-78130strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.HIGH7.525%ileMicrosoft2026-09-08
CVE-2023-26917libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validatHIGH7.558%ileMicrosoft2023-04-11
CVE-2026-90229In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Destroy the admin queue on removal TheHIGH7.410%ileNVD2026-09-17
CVE-2026-91954FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface BitsHIGH7.128%ileNVD2026-09-15
CVE-2026-92417A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the libHIGH7.149%ileNVD2026-09-16
CVE-2025-39838cifs: prevent NULL pointer dereference in UTF16 conversionHIGH7.05%ileMicrosoft2025-09-09
CVE-2025-39865tee: fix NULL pointer dereference in tee_shm_putHIGH7.06%ileMicrosoft2025-09-09
CVE-2026-76865Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filtMEDIUM6.930%ileNVD2026-09-15
CVE-2026-76868Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by aMEDIUM6.930%ileNVD2026-09-15
CVE-2026-93689WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device controMEDIUM6.8NVD2026-09-18
CVE-2026-16702IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) couldMEDIUM6.528%ileNVD2026-09-14
CVE-2026-53719Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.551%ileNVD2026-09-14
CVE-2026-65412A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7MEDIUM6.539%ileNVD2026-09-14
CVE-2026-53111bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encapMEDIUM6.52%ileMicrosoft2026-06-09
CVE-2020-28163libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-tMEDIUM6.555%ileMicrosoft2023-04-11
CVE-2023-28484In libxml2 before 2.10.4 parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently MEDIUM6.564%ileMicrosoft2023-04-11
CVE-2025-54409AIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS)MEDIUM6.215%ileMicrosoft2025-08-12
CVE-2026-23679libusb < 1.0.30 NULL Pointer Dereference in parse_interface()MEDIUM6.28%ileMicrosoft2026-05-12
CVE-2026-90782S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_itemsMEDIUM6.025%ileNVD2026-09-13
CVE-2026-42767NULL Pointer Dereference in CRMF EncryptedValue DecryptionMEDIUM5.945%ileMicrosoft2026-06-09
CVE-2025-39857net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync()MEDIUM5.824%ileMicrosoft2025-09-09
CVE-2026-90995A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (PlugMEDIUM5.51%ileNVD2026-09-14
CVE-2026-89933iio: pressure: dps310: fix NULL pointer dereference on ACPI probeMEDIUM5.510%ileMicrosoft2026-09-08
CVE-2026-90019usb: gadget: fix null pointer dereference in usb_put_function_instance()MEDIUM5.512%ileMicrosoft2026-09-08
CVE-2026-90020USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()MEDIUM5.512%ileMicrosoft2026-09-08
CVE-2026-90023usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()MEDIUM5.512%ileMicrosoft2026-09-08
CVE-2026-76781A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL poMEDIUM5.56%ileNVD2026-09-17
CVE-2025-39693drm/amd/display: Avoid a NULL pointer dereferenceMEDIUM5.55%ileMicrosoft2025-09-09
CVE-2025-39705drm/amd/display: fix a Null pointer dereference vulnerabilityMEDIUM5.54%ileMicrosoft2025-09-09
CVE-2025-39846pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region()MEDIUM5.56%ileMicrosoft2025-09-09
CVE-2025-38513wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev()MEDIUM5.56%ileMicrosoft2025-08-12
CVE-2025-38562ksmbd: fix null pointer dereference error in generate_encryptionkeyMEDIUM5.595%ileMicrosoft2025-08-12
CVE-2025-38610powercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw()MEDIUM5.56%ileMicrosoft2025-08-12
CVE-2025-38664ice: Fix a null pointer dereference in ice_copy_and_init_pkg()MEDIUM5.57%ileMicrosoft2025-08-12
CVE-2026-74734firewire: ohci: fix NULL pointer dereference in ar_context_releaseMEDIUM5.57%ileMicrosoft2026-08-11
CVE-2026-80679s390/dasd: Fix potential NULL pointer dereferenceMEDIUM5.58%ileMicrosoft2026-08-11
CVE-2026-43131drm/amd/pm: Fix null pointer dereference issueMEDIUM5.52%ileMicrosoft2026-05-12
CVE-2026-43137ASoC: SOF: Intel: hda: Fix NULL pointer dereferenceMEDIUM5.53%ileMicrosoft2026-05-12
CVE-2026-45845net/sched: taprio: fix NULL pointer dereference in class dumpMEDIUM5.52%ileMicrosoft2026-05-12
CVE-2026-45846bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()MEDIUM5.53%ileMicrosoft2026-05-12
CVE-2026-53337net: bonding: fix NULL pointer dereference in bond_do_ioctl()MEDIUM5.56%ileMicrosoft2026-07-14
CVE-2026-53382media: vidtv: fix NULL pointer dereference in vidtv_mux_push_siMEDIUM5.53%ileMicrosoft2026-07-14
CVE-2026-64190net: team: fix NULL pointer dereference in team_xmit during mode changeMEDIUM5.54%ileMicrosoft2026-07-14
CVE-2026-64511ACPI: NFIT: core: Fix possible NULL pointer dereferenceMEDIUM5.55%ileMicrosoft2026-07-14
CVE-2026-46282iio: frequency: admv1013: fix NULL pointer dereference on strMEDIUM5.52%ileMicrosoft2026-06-09
CVE-2026-53166futex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlockMEDIUM5.5Microsoft2026-06-09
CVE-2026-53177bnxt_en: Fix NULL pointer dereferenceMEDIUM5.52%ileMicrosoft2026-06-09
CVE-2026-53237gpio: mvebu: fix NULL pointer dereference in suspend/resumeMEDIUM5.56%ileMicrosoft2026-06-09
CVE-2026-53289ice: fix NULL pointer dereference in ice_reset_all_vfs()MEDIUM5.52%ileMicrosoft2026-06-09
CVE-2026-53158misc: fastrpc: Fix NULL pointer dereference in rpmsg callbackMEDIUM5.52%ileMicrosoft2026-06-09
CVE-2026-53048gfs2: prevent NULL pointer dereference during unmountMEDIUM5.52%ileMicrosoft2026-06-09
CVE-2025-68776net/hsr: fix NULL pointer dereference in prp_get_untagged_frame()MEDIUM5.511%ileMicrosoft2026-01-13
CVE-2025-68797char: applicom: fix NULL pointer dereference in ac_ioctlMEDIUM5.511%ileMicrosoft2026-01-13
CVE-2026-22998nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovecMEDIUM5.553%ileMicrosoft2026-01-13
CVE-2025-61143libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.MEDIUM5.52%ileMicrosoft2026-02-10
CVE-2024-38571thermal/drivers/tsens: Fix null pointer dereferenceMEDIUM5.514%ileMicrosoft2024-06-11
CVE-2023-2166A null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may noMEDIUM5.510%ileMicrosoft2023-04-11
CVE-2023-2177A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If sMEDIUM5.511%ileMicrosoft2023-04-11
CVE-2023-28327A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux KeMEDIUM5.59%ileMicrosoft2023-04-11
CVE-2023-28328A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux KernelMEDIUM5.513%ileMicrosoft2023-04-11
CVE-2026-90485A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegMEDIUM5.46%ileNVD2026-09-12
CVE-2026-22693Null Pointer Dereference in SubtableUnicodesCache::create leading to DoSMEDIUM5.338%ileMicrosoft2026-01-13
CVE-2023-26916libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at MEDIUM5.361%ileMicrosoft2023-04-11
CVE-2026-47143Capstone has a NULL Pointer Dereference with 3DNow! opcodesMEDIUM5.134%ileMicrosoft2026-07-14
CVE-2023-53401mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required()MEDIUM4.73%ileMicrosoft2025-09-09
CVE-2026-68362wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_beginMEDIUM4.77%ileMicrosoft2026-08-11
CVE-2023-1382A data race flaw was found in the Linux kernel between where con is allocated and con->sock is set. This issue leads to MEDIUM4.78%ileMicrosoft2023-04-11
CVE-2026-81005ipmi: si: Fix NULL pointer dereference after failed registrationMEDIUM4.28%ileMicrosoft2026-09-08
CVE-2026-80917PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systemsMEDIUM4.16%ileMicrosoft2026-09-08
CVE-2026-33970An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 21LOW3.510%ileNVD2026-09-14
CVE-2025-10823axboe fio options.c str_buffer_pattern_cb null pointer dereferenceLOW3.34%ileMicrosoft2025-09-09
CVE-2025-8835JasPer Image Color Space Conversion jas_image.c jas_image_chclrspc null pointer dereferenceLOW3.312%ileMicrosoft2025-08-12
CVE-2025-8844NASM Netwide Assember preproc.c parse_smacro_template null pointer dereferenceLOW3.318%ileMicrosoft2025-08-12
CVE-2025-15504lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereferenceLOW3.319%ileMicrosoft2026-01-13
CVE-2026-86141xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., iLOW2.92%ileMicrosoft2026-09-08
CVE-2024-13978LibTIFF fax2ps tiff2pdf.c t2p_read_tiff_init null pointer dereferenceLOW2.59%ileMicrosoft2025-08-12
CVE-2025-8534libtiff tiff2ps tiff2ps.c PS_Lvl2page null pointer dereferenceLOW2.58%ileMicrosoft2025-08-12
CVE-2026-93588ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reLOW2.3NVD2026-09-18
CVE-2026-90792A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegrLOW2.133%ileNVD2026-09-14
CVE-2026-92413A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability isLOW2.137%ileNVD2026-09-16
CVE-2026-93312A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JLOW2.127%ileNVD2026-09-18
CVE-2026-90573A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file LOW1.92%ileNVD2026-09-13
CVE-2026-90576A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of thLOW1.96%ileNVD2026-09-13
CVE-2026-90609A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegrapLOW1.92%ileNVD2026-09-14
CVE-2026-90622A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.specLOW1.96%ileNVD2026-09-14
CVE-2026-90802A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of theLOW1.92%ileNVD2026-09-14
CVE-2026-90828A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible LOW1.95%ileNVD2026-09-14
CVE-2026-90829A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the fLOW1.96%ileNVD2026-09-14
CVE-2026-90830A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of tLOW1.95%ileNVD2026-09-14
CVE-2026-91779A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of LOW1.92%ileNVD2026-09-15
CVE-2026-91780A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bLOW1.92%ileNVD2026-09-15
CVE-2026-91781A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_indeLOW1.93%ileNVD2026-09-15
CVE-2026-91782A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynreLOW1.93%ileNVD2026-09-15
CVE-2026-80963In the Linux kernel, the following vulnerability has been resolved: dm-stats: fix a crash if allocation of per-cpu dataUNKNOWN8%ileNVD2026-09-11
CVE-2026-89552In the Linux kernel, the following vulnerability has been resolved: params: fix charp corruption on allocation failure UNKNOWN6%ileNVD2026-09-11
CVE-2026-89734In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Fix null pointer dereference in uUNKNOWN6%ileNVD2026-09-11
CVE-2026-89770In the Linux kernel, the following vulnerability has been resolved: iomap: don't free integrity payload that doesn't exUNKNOWN4%ileNVD2026-09-11
CVE-2026-89807In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: guard against NULL restore_mqd in CRIU UNKNOWN10%ileNVD2026-09-16
CVE-2026-89958In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix dereference matrix_mdev->kvm withUNKNOWN10%ileNVD2026-09-16
CVE-2026-89966In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb_cma: fix null nodemask dereference in huUNKNOWN9%ileNVD2026-09-16
CVE-2026-38999A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0UNKNOWN43%ileNVD2026-09-16
CVE-2026-90115In the Linux kernel, the following vulnerability has been resolved: xsk: fix NULL pointer dereference in __xsk_rcv() IUNKNOWN10%ileNVD2026-09-17
CVE-2026-90139In the Linux kernel, the following vulnerability has been resolved: fuse: check for NULL root inode in fuse_fill_super_UNKNOWN10%ileNVD2026-09-17
CVE-2026-90144In the Linux kernel, the following vulnerability has been resolved: dpll: fix NULL deref in dpll_device_ops() during teUNKNOWN9%ileNVD2026-09-17
CVE-2026-90148In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix incorrect argument passed to nfs4_deleteUNKNOWN10%ileNVD2026-09-17
CVE-2026-90192In the Linux kernel, the following vulnerability has been resolved: mailbox: qcom-cpucp: handle NULL data in send_data UNKNOWN10%ileNVD2026-09-17
CVE-2026-90202In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL bUNKNOWN12%ileNVD2026-09-17
CVE-2026-90271In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Fix a NULL pointer dereference on unbindiUNKNOWN9%ileNVD2026-09-17
CVE-2026-90281In the Linux kernel, the following vulnerability has been resolved: phy: qcom: snps-femto-v2: Fix possible NULL-deref oUNKNOWN12%ileNVD2026-09-17
CVE-2026-90397In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix NULL dereference in IRQ haUNKNOWN10%ileNVD2026-09-17
CVE-2026-90400In the Linux kernel, the following vulnerability has been resolved: md: recheck spare changes before starting sync remUNKNOWN6%ileNVD2026-09-17
CVE-2026-92493In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate-ut: Skip tests when amd-pstate UNKNOWN6%ileNVD2026-09-17
CVE-2026-92500In the Linux kernel, the following vulnerability has been resolved: ext4: use fsdata to track inline data write state aUNKNOWN7%ileNVD2026-09-17
CVE-2026-93068In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix DM I2C teardown race DM I2C aUNKNOWN10%ileNVD2026-09-17
CVE-2026-93114In the Linux kernel, the following vulnerability has been resolved: platform/surface: acpi-notify: Check ACPI companionUNKNOWN7%ileNVD2026-09-17
CVE-2026-93115In the Linux kernel, the following vulnerability has been resolved: platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION(UNKNOWN11%ileNVD2026-09-17
CVE-2026-93124In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wireless: Fail probe when there UNKNOWN5%ileNVD2026-09-17
CVE-2026-93139In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: Fix hung_queue_db_array loop limit UNKNOWN9%ileNVD2026-09-17
CVE-2026-93180In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NPD issue on partial unmap of an eUNKNOWN12%ileNVD2026-09-17
CVE-2026-19024HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value MessageUNKNOWN3%ileMicrosoft2026-08-11
CVE-2026-7259Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()UNKNOWN10%ileMicrosoft2026-05-12
CVE-2026-7262NULL pointer dereference in SOAP apache:Map decoder with missing <value>UNKNOWN54%ileMicrosoft2026-05-12
CVE-2026-56288NULL Pointer Dereference in GNU patchUNKNOWN6%ileMicrosoft2026-07-14
FG-IR-26-173Null Pointer Dereference in Log ReportUNKNOWNFortinet2026-09-08