VulnSea

CWE-476

CVEs classified under CWE-476, newest first.

373 CVEsRSS

CVE-2026-27214Medium· 5.5
6mo ago

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing d…

▾ Sunlitadobe · substance_3d_painterEPSS 0.23%via NVD
CVE-2026-21364Medium· 5.5
6mo ago

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing d…

▾ Sunlitadobe · substance_3d_painterEPSS 0.13%via NVD
CVE-2026-21363Medium· 5.5
6mo ago

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing d…

▾ Sunlitadobe · substance_3d_painterEPSS 0.13%via NVD
CVE-2025-62817High· 7.5
6mo ago

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of session->ncp_hdr_buf in __pilot_parsing_ncp() causes a denial of service.

▾ Twilightsamsung · exynos_1280_firmwareEPSS 0.29%via NVD
CVE-2026-21350Medium· 5.5
7mo ago

After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption …

▾ Sunlitadobe · after_effectsEPSS 0.14%via NVD
CVE-2026-21338Medium· 5.5
7mo ago

Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing …

▾ Sunlitadobe · substance_3d_designerEPSS 0.14%via NVD
CVE-2026-21336Medium· 5.5
7mo ago

Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing …

▾ Sunlitadobe · substance_3d_designerEPSS 0.14%via NVD
CVE-2026-23831Medium· 5.3
8mo ago

github.com/sigstore/rekor: Rekor denial of service (CVE-2026-23831)

Rekor’s cose v0.0.1 entry implementation can panic on attacker-controlled input when canonicalizing a proposed entry with an empty spec.message. validate() returns nil (success) when message is empty, leaving sign1Msg uninitialized, and Ca…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.44%via CSAF
CVE-2026-21301Medium· 5.5
8mo ago

Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open …

▾ Sunlitadobe · substance_3d_modelerEPSS 0.17%via NVD
CVE-2026-21300Medium· 5.5
8mo ago

Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Substance3D - Modeler versions 1.22.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open …

▾ Sunlitadobe · substance_3d_modelerEPSS 0.17%via NVD
CVE-2026-21288Medium· 5.5
8mo ago

Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service

Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disru…

▾ Sunlitadobe · illustratorEPSS 0.21%via NVD
CVE-2026-20875High· 7.5
8mo ago

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.6%via NVD
CVE-2025-68742Medium· 4.7
9mo ago

kernel: bpf: Fix invalid prog->stats access when update_effective_progs fails (CVE-2025-68742)

An invalid memory access vulnerability was found in the Linux kernel's BPF cgroup subsystem. When update_effective_progs fails due to allocation failure (such as from fault injection), the code replaces the program with dummy_bpf_prog. If …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2025-65835Medium· 6.2
9mo ago

The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter…

The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter…

▾ Sunliteddyverbruggen · cordova-plugin-x-socialsharingEPSS 0.28%via NVD
CVE-2025-65296Medium· 6.5
9mo ago

NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.

NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing enable denial-of-service attacks through malformed JSON inputs.

▾ Sunlitaqara · hub_m2_firmwareEPSS 0.28%via NVD
CVE-2025-6966Medium· 5.5
9mo ago

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

▾ Sunlitubuntu · python-aptEPSS 0.14%via NVD
CVE-2025-64527Medium· 6.5
9mo ago

Envoy is a high-performance edge/middle/service proxy

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy crashes when JWT authentication is configured with the remote JWKS fetching, allow_missing_or_failed is enabled, multiple JWT …

▾ Sunlitenvoyproxy · envoyEPSS 0.53%via NVD
CVE-2025-20755Medium· 5.3
9mo ago

In Modem, there is a possible application crash due to improper input validation

In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privile…

▾ Sunlitmediatek · nr15EPSS 0.37%via NVD
CVE-2025-7007High· 7.5
10mo ago

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to crash.This issue affects Antivirus: 16.0.0; Anitvirus: 3.0.3.

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to crash.This issue affects Antivirus: 16.0.0; Anitvirus: 3.0.3.

▾ TwilightEPSS 0.11%via NVD
CVE-2022-50535Medium· 5.5
11mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential null-deref in dm_resume [Why] Fixing smatch error: dm_resume() error: we previously assumed 'aconnector->dc_link' could be null [How] C…

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential null-deref in dm_resume [Why] Fixing smatch error: dm_resume() error: we previously assumed 'aconnector->dc_link' could be null [How] C…

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2022-50527Medium· 5.5
11mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix size validation for non-exclusive domains (v4) Fix amdgpu_bo_validate_size() to check whether the TTM domain manager for the requested memory exists, e…

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix size validation for non-exclusive domains (v4) Fix amdgpu_bo_validate_size() to check whether the TTM domain manager for the requested memory exists, e…

▾ Sunlitlinux · linux_kernelEPSS 0.15%via NVD
CVE-2025-39936Medium· 5.5
11mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() When 9770b428b1a2 ("crypto: ccp - Move dev_info/err messages for SEV/SNP init and …

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() When 9770b428b1a2 ("crypto: ccp - Move dev_info/err messages for SEV/SNP init and …

▾ Sunlitlinux · linux_kernelEPSS 0.14%via NVD
CVE-2025-60019Low· 3.7
1y ago

glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines

glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.

▾ SunlitEPSS 0.36%via NVD
CVE-2023-53292Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none After grabbing q->sysfs_lock, q->elevator may become NULL because of elevator switch. Fix the NU…

In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none After grabbing q->sysfs_lock, q->elevator may become NULL because of elevator switch. Fix the NU…

▾ Sunlitlinux · linux_kernelEPSS 0.15%via NVD
CVE-2022-50336Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add null pointer check to attr_load_runs_vcn Some metadata files are handled before MFT

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add null pointer check to attr_load_runs_vcn Some metadata files are handled before MFT. This adds a null pointer check for some corner cases that could lead…

▾ Sunlitlinux · linux_kernelEPSS 0.15%via NVD
CVE-2022-50262Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate BOOT record_size When the NTFS BOOT record_size field < 0, it represents a shift value

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate BOOT record_size When the NTFS BOOT record_size field < 0, it represents a shift value. However, there is no sanity check on the shift result and th…

▾ Sunlitlinux · linux_kernelEPSS 0.15%via NVD
CVE-2025-9817High· 7.8
1y ago

SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service

SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service

▾ Twilightwireshark · wiresharkEPSS 0.21%via NVD
CVE-2025-30274Medium· 6.5
1y ago

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in t…

▾ Sunlitqnap · qtsEPSS 0.31%via NVD
CVE-2025-30272Medium· 6.5
1y ago

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in t…

▾ Sunlitqnap · qtsEPSS 0.31%via NVD
CVE-2025-30268Medium· 6.5
1y ago

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. …

▾ Sunlitqnap · qtsEPSS 0.37%via NVD
CWE-476 vulnerabilities (CVEs) — page 9 · VulnSea