VulnSea

CWE-476

CVEs classified under CWE-476, newest first.

373 CVEsRSS

CVE-2026-42285High· 7.5
4mo ago

github.com/osrg/gobgp: GoBGP: Denial of Service due to specially crafted BGP UPDATE message (CVE-2026-42285)

A flaw was found in GoBGP 4.4.0. A crafted BGP UPDATE with inconsistent attribute lengths mishandles the withdraw state transition in AdjRib.Update, causing a nil pointer dereference and full process crash. Fixed in GoBGP 4.5.0.

▾ TwilightRed Hat · github.com/osrg/gobgp/v4EPSS 0.60%via CSAF
CVE-2026-41642High· 7.5
4mo ago

github.com/osrg/gobgp: GoBGP: Denial of Service via malformed BGP UPDATE message (CVE-2026-41642)

A flaw was found in GoBGP 4.3.0. A malformed BGP UPDATE with an unrecognized Path Attribute marked as well-known is not rejected cleanly, triggering a nil pointer dereference that crashes the GoBGP daemon. Fixed in GoBGP 4.4.0.

▾ TwilightRed Hat · github.com/osrg/gobgp/v4EPSS 0.60%via CSAF
CVE-2026-43216Medium· 5.5
4mo ago

In the Linux kernel, the following vulnerability has been resolved: net: Drop the lock in skb_may_tx_timestamp() skb_may_tx_timestamp() may acquire sock::sk_callback_lock

In the Linux kernel, the following vulnerability has been resolved: net: Drop the lock in skb_may_tx_timestamp() skb_may_tx_timestamp() may acquire sock::sk_callback_lock. The lock must not be taken in IRQ context, only softirq is okay…

▾ Sunlitlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-31755Medium· 5.5
4mo ago

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: gadget: fix NULL pointer dereference in ep_queue When the gadget endpoint is disabled or not yet configured, the ep->desc pointer can be NULL

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: gadget: fix NULL pointer dereference in ep_queue When the gadget endpoint is disabled or not yet configured, the ep->desc pointer can be NULL. This leads t…

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-40355Medium· 5.9PoC
5mo ago

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trig…

▾ Twilightmit · kerberos_5EPSS 0.79%via NVD
CVE-2026-6845Medium· 5.0
5mo ago

A flaw was found in binutils, specifically within the `readelf` utility

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format …

▾ Sunlitgnu · binutilsEPSS 0.14%via NVD
CVE-2026-32071High· 7.5
5mo ago

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-32216Medium· 5.5
5mo ago

Windows Redirected Drive Buffering System Denial of Service Vulnerability

Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.

▾ SunlitMicrosoft · Windows 11 version 26H1EPSS 0.40%via CVEORG
CVE-2026-26173High· 7.0
5mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-39956Medium· 6.1
5mo ago

jq is a command-line JSON processor

jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relie…

▾ Sunlitjqlang · jqEPSS 0.17%via NVD
CVE-2026-1584High· 7.5
5mo ago

A flaw was found in gnutls

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to…

▾ Twilightgnu · gnutlsEPSS 1.3%via NVD
CVE-2026-31411Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc p…

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() Reproducer available at [1]. The ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc p…

▾ Sunlitlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-5745Medium· 5.5
5mo ago

A flaw was found in libarchive

A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default…

▾ Sunlitlibarchive · libarchiveEPSS 0.17%via NVD
CVE-2026-28390High· 7.5
5mo ago

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authen…

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authen…

▾ Twilightopenssl · opensslEPSS 0.80%via NVD
CVE-2026-28389High· 7.5
5mo ago

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentica…

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentica…

▾ Twilightopenssl · opensslEPSS 2.4%via NVD
CVE-2026-28388High· 7.5
5mo ago

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a…

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a…

▾ Twilightopenssl · opensslEPSS 2.5%via NVD
CVE-2026-5590Medium· 6.4
5mo ago

A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released

A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context da…

▾ Sunlitzephyrproject · zephyrEPSS 0.27%via NVD
CVE-2026-31404High· 7.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: NFSD: Defer sub-object cleanup in export put callbacks svc_export_put() calls path_put() and auth_domain_put() immediately when the last reference drops, before the RC…

In the Linux kernel, the following vulnerability has been resolved: NFSD: Defer sub-object cleanup in export put callbacks svc_export_put() calls path_put() and auth_domain_put() immediately when the last reference drops, before the RC…

▾ Twilightlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-31397High· 7.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix use of NULL folio in move_pages_huge_pmd() move_pages_huge_pmd() handles UFFDIO_MOVE for both normal THPs and huge zero pages

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix use of NULL folio in move_pages_huge_pmd() move_pages_huge_pmd() handles UFFDIO_MOVE for both normal THPs and huge zero pages. For the huge zero p…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2026-31394Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations ieee80211_chan_bw_change() iterates all stations and accesses link->reserved.oper via sta->sdata->…

In the Linux kernel, the following vulnerability has been resolved: mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations ieee80211_chan_bw_change() iterates all stations and accesses link->reserved.oper via sta->sdata->…

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-23475Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: spi: fix statistics allocation The controller per-cpu statistics is not allocated until after the controller has been registered with driver core, which leaves a windo…

In the Linux kernel, the following vulnerability has been resolved: spi: fix statistics allocation The controller per-cpu statistics is not allocated until after the controller has been registered with driver core, which leaves a windo…

▾ Sunlitlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-23467Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/i915/dmc: Fix an unlikely NULL pointer deference at probe intel_dmc_update_dc6_allowed_count() oopses when DMC hasn't been initialized, and dmc is thus NULL. That…

In the Linux kernel, the following vulnerability has been resolved: drm/i915/dmc: Fix an unlikely NULL pointer deference at probe intel_dmc_update_dc6_allowed_count() oopses when DMC hasn't been initialized, and dmc is thus NULL. That…

▾ Sunlitlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-23460Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: net/rose: fix NULL pointer dereference in rose_transmit_link on reconnect syzkaller reported a bug [1], and the reproducer is available at [2]. ROSE sockets use four …

In the Linux kernel, the following vulnerability has been resolved: net/rose: fix NULL pointer dereference in rose_transmit_link on reconnect syzkaller reported a bug [1], and the reproducer is available at [2]. ROSE sockets use four …

▾ Sunlitlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-23435Medium· 5.5
5mo ago

In the Linux kernel, the following vulnerability has been resolved: perf/x86: Move event pointer setup earlier in x86_pmu_enable() A production AMD EPYC system crashed with a NULL pointer dereference in the PMU NMI handler: BUG: ker…

In the Linux kernel, the following vulnerability has been resolved: perf/x86: Move event pointer setup earlier in x86_pmu_enable() A production AMD EPYC system crashed with a NULL pointer dereference in the PMU NMI handler: BUG: ker…

▾ Sunlitlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-0968Low· 3.1
6mo ago

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check c…

▾ Sunlitlibssh · libsshEPSS 0.44%via NVD
CVE-2026-29785High· 7.5
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect …

▾ Twilightlinuxfoundation · nats-serverEPSS 0.97%via NVD
CVE-2026-32249Medium· 5.3
6mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorre…

▾ Sunlitvim · vimEPSS 0.19%via NVD
CVE-2026-27218Medium· 5.5
6mo ago

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing d…

▾ Sunlitadobe · substance_3d_painterEPSS 0.23%via NVD
CVE-2026-27217Medium· 5.5
6mo ago

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing d…

▾ Sunlitadobe · substance_3d_painterEPSS 0.23%via NVD
CVE-2026-27215Medium· 5.5
6mo ago

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing d…

▾ Sunlitadobe · substance_3d_painterEPSS 0.23%via NVD
CWE-476 vulnerabilities (CVEs) — page 8 · VulnSea