CWE-476
CVEs classified under CWE-476, newest first.
373 CVEsRSS
CVE-2026-67288High· 7.5⚖ disputedFreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emu…
CVE-2026-47427High· 7.5GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
CVE-2026-17500Medium· 5.3A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0
A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched …
CVE-2026-64373Medium· 4.7In the Linux kernel, the following vulnerability has been resolved: cpufreq: Fix hotplug-suspend race during reboot During system reboot, cpufreq_suspend() is called via the kernel_restart() -> device_shutdown() path
In the Linux kernel, the following vulnerability has been resolved: cpufreq: Fix hotplug-suspend race during reboot During system reboot, cpufreq_suspend() is called via the kernel_restart() -> device_shutdown() path. Unlike the normal…
CVE-2026-64405Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() hci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection was pending, but hdev->sent_cmd can b…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() hci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection was pending, but hdev->sent_cmd can b…
CVE-2026-64404Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() iso_conn_big_sync() drops the socket lock to call hci_get_route() and then re-acquires it, but derefere…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() iso_conn_big_sync() drops the socket lock to call hci_get_route() and then re-acquires it, but derefere…
CVE-2026-64403High· 7.1In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before reading conf opt value l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and i…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before reading conf opt value l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and i…
CVE-2026-64358Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: cancel workqueue on release for supported platforms only Since a recent fix the mtk_jpeg_release function cancels any pending or running work present …
In the Linux kernel, the following vulnerability has been resolved: media: mtk-jpeg: cancel workqueue on release for supported platforms only Since a recent fix the mtk_jpeg_release function cancels any pending or running work present …
CVE-2026-64325Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon This patch is based on a BUG as reported by Bongani Hlope at https://lore.kernel.org/all/20260502125824.4…
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon This patch is based on a BUG as reported by Bongani Hlope at https://lore.kernel.org/all/20260502125824.4…
GHSA-jpcw-4wr7-c3vqMedium· 5.3kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
GHSA-qh5g-q395-cx4jLow· 3.7ImageMagick: Heap-use-after-free via XMP profile could result in a crash
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
CVE-2026-55984Low· 2.7Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-64192Medium· 6.4In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized When CONFIG_BPF_LSM=y is set, BPF inode storage maps (BPF_MAP_TYPE_INODE_STORAGE) are compi…
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized When CONFIG_BPF_LSM=y is set, BPF inode storage maps (BPF_MAP_TYPE_INODE_STORAGE) are compi…
CVE-2026-64079Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: allocate hook ops while under mutex arp/ip(6)t_register_table() add the table to the per-netns list via xt_register_table() before allocating the …
In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: allocate hook ops while under mutex arp/ip(6)t_register_table() add the table to the per-netns list via xt_register_table() before allocating the …
CVE-2026-62309High· 7.5CoreDNS is a DNS server written in Go
CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 …
CVE-2026-57976Medium· 6.5Windows Active Directory Domain Services Denial of Service Vulnerability
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
CVE-2026-50315High· 7.8Windows Image Acquisition Elevation of Privilege Vulnerability
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
CVE-2026-50366Medium· 6.5Windows Active Directory Domain Services Denial of Service Vulnerability
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
CVE-2026-50673High· 7.8Windows Kernel Elevation of Privilege Vulnerability
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56168Medium· 6.5Windows SMB Server Denial of Service Vulnerability
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
CVE-2026-56288Medium· 5.5GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) d…
CVE-2026-58250High· 7.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the se…
CVE-2026-44512Medium· 5.5ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
CVE-2026-14324Medium· 6.5RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
CVE-2025-10998Low· 5.5Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
CVE-2025-10999Medium· 5.5Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
CVE-2026-2705Low· 5.5Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
CVE-2026-3408Low· 5.5Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
CVE-2026-53313Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths In dc_dmub_srv_log_diagnostic_data() and dc_dmub_srv_enable_dpia_trace(). Both functions check: …
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths In dc_dmub_srv_log_diagnostic_data() and dc_dmub_srv_enable_dpia_trace(). Both functions check: …
CVE-2026-53281High· 8.8In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit 60f030f7418d ("iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE") fixed a NULL pointer derefer…
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption Commit 60f030f7418d ("iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE") fixed a NULL pointer derefer…