VulnSea

CWE-476

CVEs classified under CWE-476, newest first.

373 CVEsRSS

CVE-2026-67288High· 7.5⚖ disputed
1mo ago

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emu…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via NVD
CVE-2026-47427High· 7.5
2mo ago

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

▾ Twilightgithub · github.com/github/github-mcp-serverEPSS 0.77%via GHSA
CVE-2026-17500Medium· 5.3
2mo ago

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched …

▾ SunlitEPSS 0.72%via NVD
CVE-2026-64373Medium· 4.7
2mo ago

In the Linux kernel, the following vulnerability has been resolved: cpufreq: Fix hotplug-suspend race during reboot During system reboot, cpufreq_suspend() is called via the kernel_restart() -> device_shutdown() path

In the Linux kernel, the following vulnerability has been resolved: cpufreq: Fix hotplug-suspend race during reboot During system reboot, cpufreq_suspend() is called via the kernel_restart() -> device_shutdown() path. Unlike the normal…

▾ Sunlitlinux · linux_kernelEPSS 0.09%via NVD
CVE-2026-64405Medium· 5.5
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() hci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection was pending, but hdev->sent_cmd can b…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() hci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection was pending, but hdev->sent_cmd can b…

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-64404Medium· 5.5
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() iso_conn_big_sync() drops the socket lock to call hci_get_route() and then re-acquires it, but derefere…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() iso_conn_big_sync() drops the socket lock to call hci_get_route() and then re-acquires it, but derefere…

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-64403High· 7.1
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before reading conf opt value l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and i…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before reading conf opt value l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and i…

▾ Twilightlinux · linux_kernelEPSS 0.40%via NVD
CVE-2026-64358Medium· 5.5
2mo ago

In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: cancel workqueue on release for supported platforms only Since a recent fix the mtk_jpeg_release function cancels any pending or running work present …

In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: cancel workqueue on release for supported platforms only Since a recent fix the mtk_jpeg_release function cancels any pending or running work present …

▾ Sunlitlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-64325Medium· 5.5
2mo ago

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon This patch is based on a BUG as reported by Bongani Hlope at https://lore.kernel.org/all/20260502125824.4…

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon This patch is based on a BUG as reported by Bongani Hlope at https://lore.kernel.org/all/20260502125824.4…

▾ Sunlitlinux · linux_kernelEPSS 0.14%via NVD
GHSA-jpcw-4wr7-c3vqMedium· 5.3
2mo ago

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

▾ Sunlitgetkin · github.com/getkin/kin-openapivia GHSA
GHSA-qh5g-q395-cx4jLow· 3.7
2mo ago

ImageMagick: Heap-use-after-free via XMP profile could result in a crash

ImageMagick: Heap-use-after-free via XMP profile could result in a crash

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-55984Low· 2.7
2mo ago

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.46%via GHSA
CVE-2026-64192Medium· 6.4
2mo ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized When CONFIG_BPF_LSM=y is set, BPF inode storage maps (BPF_MAP_TYPE_INODE_STORAGE) are compi…

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized When CONFIG_BPF_LSM=y is set, BPF inode storage maps (BPF_MAP_TYPE_INODE_STORAGE) are compi…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.12%via NVD
CVE-2026-64079Medium· 5.5
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: allocate hook ops while under mutex arp/ip(6)t_register_table() add the table to the per-netns list via xt_register_table() before allocating the …

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: allocate hook ops while under mutex arp/ip(6)t_register_table() add the table to the per-netns list via xt_register_table() before allocating the …

▾ Sunlitlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-62309High· 7.5
2mo ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 …

▾ TwilightRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.17EPSS 0.66%via NVD
CVE-2026-57976Medium· 6.5
2mo ago

Windows Active Directory Domain Services Denial of Service Vulnerability

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 1.1%via CVEORG
CVE-2026-50315High· 7.8
2mo ago

Windows Image Acquisition Elevation of Privilege Vulnerability

Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.33%via CVEORG
CVE-2026-50366Medium· 6.5
2mo ago

Windows Active Directory Domain Services Denial of Service Vulnerability

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 1.1%via CVEORG
CVE-2026-50673High· 7.8
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.21%via CVEORG
CVE-2026-56168Medium· 6.5
2mo ago

Windows SMB Server Denial of Service Vulnerability

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 1.1%via CVEORG
CVE-2026-56288Medium· 5.5
2mo ago

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) d…

▾ Sunlitgnu · patchEPSS 0.17%via NVD
CVE-2026-58250High· 7.5
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the se…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.74%via NVD
CVE-2026-44512Medium· 5.5
2mo ago

ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)

ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)

▾ Sunlitonnx · onnxEPSS 0.19%via OSV
CVE-2026-14324Medium· 6.5
2mo ago

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

▾ SunlitEPSS 0.23%via NVD
CVE-2025-10998Low· 5.5
2mo ago

Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines

Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines

▾ Sunlitopenbabel · openbabelEPSS 0.21%via GHSA
CVE-2025-10999Medium· 5.5
2mo ago

Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt

Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt

▾ Sunlitopenbabel · openbabelEPSS 0.25%via GHSA
CVE-2026-2705Low· 5.5
2mo ago

Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge

Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge

▾ Sunlitopenbabel · openbabelEPSS 0.77%via GHSA
CVE-2026-3408Low· 5.5
2mo ago

Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence

Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence

▾ Sunlitopenbabel · openbabelEPSS 0.68%via GHSA
CVE-2026-53313Medium· 5.5
3mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths In dc_dmub_srv_log_diagnostic_data() and dc_dmub_srv_enable_dpia_trace(). Both functions check: …

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths In dc_dmub_srv_log_diagnostic_data() and dc_dmub_srv_enable_dpia_trace(). Both functions check: …

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-53281High· 8.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit 60f030f7418d ("iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE") fixed a NULL pointer derefer…

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit 60f030f7418d ("iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE") fixed a NULL pointer derefer…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CWE-476 vulnerabilities (CVEs) — page 6 · VulnSea