Vulnerabilities (CVE)

Filtered by CWE-476
Total 3936 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-48073 1 Openexr 1 Openexr 2025-08-13 N/A 6.2 MEDIUM
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.
CVE-2025-24515 2025-08-13 N/A 6.5 MEDIUM
NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
CVE-2025-52585 2025-08-13 N/A 7.5 HIGH
When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2023-27336 1 Softing 3 Edgeaggregator, Edgeconnector, Secure Integration Server 2025-08-13 N/A 7.5 HIGH
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OPC client certificates. The issue results from dereferencing a NULL pointer. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20508.
CVE-2025-47807 1 Gstreamer Project 1 Gstreamer 2025-08-12 N/A 5.5 MEDIUM
In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.
CVE-2025-47808 1 Gstreamer Project 1 Gstreamer 2025-08-12 N/A 5.6 MEDIUM
In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.
CVE-2025-26690 1 Openatom 1 Openharmony 2025-08-12 N/A 3.3 LOW
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
CVE-2025-8183 1 D3tn 1 Ud3tn 2025-08-11 N/A 7.5 HIGH
NULL Pointer Dereference in µD3TN via non-singleton destination Endpoint Identifier allows remote attacker to reliably cause DoS
CVE-2025-8865 2025-08-11 N/A N/A
The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An authenticated attacker could exploit this issue to crash the YCQL tablet server, resulting in a denial of service.
CVE-2023-33109 1 Qualcomm 620 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 617 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
CVE-2025-21433 1 Qualcomm 550 215 Mobile, 215 Mobile Firmware, Apq8017 and 547 more 2025-08-11 N/A 6.2 MEDIUM
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
CVE-2023-24847 1 Qualcomm 514 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 511 more 2025-08-11 N/A 7.5 HIGH
Transient DOS in Modem while allocating DSM items.
CVE-2023-43522 1 Qualcomm 572 Aqt1000, Aqt1000 Firmware, Ar8035 and 569 more 2025-08-11 N/A 7.5 HIGH
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
CVE-2023-33089 1 Qualcomm 456 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 453 more 2025-08-11 N/A 7.5 HIGH
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
CVE-2024-53024 1 Qualcomm 332 Ar8035, Ar8035 Firmware, Csra6620 and 329 more 2025-08-11 N/A 7.8 HIGH
Memory corruption in display driver while detaching a device.
CVE-2023-33088 1 Qualcomm 612 315 5g Iot Modem, 315 5g Iot Modem Firmware, Aqt1000 and 609 more 2025-08-11 N/A 8.4 HIGH
Memory corruption when processing cmd parameters while parsing vdev.
CVE-2025-22037 1 Linux 1 Linux Kernel 2025-08-09 N/A 5.5 MEDIUM
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn->preauth_info is not allocated. This patch add KSMBD_SESS_NEED_SETUP status of connection to ignore session setup request if smb2 negotiate phase is not complete.
CVE-2025-8735 2025-08-08 1.7 LOW 3.3 LOW
A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
CVE-2024-20339 1 Cisco 1 Firepower Threat Defense Software 2025-08-08 N/A 8.6 HIGH
A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an issue that occurs when TLS traffic is processed. An attacker could exploit this vulnerability by sending certain TLS traffic over IPv4 through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition and impacting traffic to and through the affected device.
CVE-2023-32171 1 Unified-automation 1 Uagateway 2025-08-08 N/A 6.5 MEDIUM
Unified Automation UaGateway OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability. The specific flaw exists within the ImportCsv method. A crafted XML payload can cause a null pointer dereference. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20495.