Skip to main content

CWE archive

CWE-476 CVEs

Programmatic archive

5,433 CVEs tagged with CWE-476119 Critical, 1,293 High, 3,808 Medium, 212 Low, 1 Unrated.

CVE-2025-70102

Published Jun 15, 2026

A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code perfor…

CVSS 6.3 · Medium

CVE-2025-55663

Published Jun 15, 2026

A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a craft…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55649

Published Jun 15, 2026

A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a craf…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55643

Published Jun 15, 2026

A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a craft…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55641

Published Jun 15, 2026

A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7018

Published Jun 12, 2026

Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus engine process. This issue…

CVSS 5.5 · Medium

CVE-2026-53463

Published Jun 10, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when passing incorrect arguments in the di…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24716

Published Jun 10, 2026

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exp…

CVSS 1.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22899

Published Jun 10, 2026

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a…

CVSS 1.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66281

Published Jun 10, 2026

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a de…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62850

Published Jun 10, 2026

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exp…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-45541

Published Jun 10, 2026

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subpro…

CVSS 7.5 · High
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-9752

Published Jun 9, 2026

An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-win…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9743

Published Jun 9, 2026

In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cursor, t…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-55659

Published Jun 9, 2026

A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafte…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55657

Published Jun 9, 2026

A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a craf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55651

Published Jun 9, 2026

A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-34704

Published Jun 9, 2026

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker coul…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34703

Published Jun 9, 2026

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker coul…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42767

Published Jun 9, 2026

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact summary: A NULL po…

CVSS 5.9 · Medium
evidence mentions
7
Buzz score
35.8
Vendor/product tagsBeta · best-effort

CVE-2026-42766

Published Jun 9, 2026

Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointer dereference lead…

CVSS 5.9 · Medium
evidence mentions
7
Buzz score
35.8
Vendor/product tagsBeta · best-effort

CVE-2026-42765

Published Jun 9, 2026

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified ch…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-42764

Published Jun 9, 2026

Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact su…

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort
Showing 126-150 of 5,433 CVEsPage 6 of 218