Catching NullPointerException should not be used as an alternative to programmatic checks to prevent dereferencing a null pointer.
Volume of CVEs assigned to CWE-395 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27466CRITICAL [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
There are multiple issues related to the handling | Sep 11, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-58142CRITICAL [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
There are multiple issues related to the handling | Sep 11, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-15514HIGH Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-en | Jan 12, 2026 | 7.5 | 26 | NO | NO |
CVE-2022-2832HIGH A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity. | Aug 16, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-29508HIGH Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access. | May 10, 2023 | 7.8 | 25 | NO | NO |
CVE-2024-27658MEDIUM D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafte | Feb 29, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-25071MEDIUM NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable den | Nov 14, 2023 | 5.5 | 19 | NO | NO |
CVE-2022-42878MEDIUM Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable in | May 10, 2023 | 5.5 | 19 | NO | NO |
CVE-2024-36275MEDIUM NULL pointer dereference in some Intel(R) Optane(TM) PMem Management software versions before CR_MGMT_02.00.00.4040, CR_MGMT_03.00.00.0499 may allow a authenticated user to potenti | Nov 13, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-23904MEDIUM NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | Sep 16, 2024 | 6.1 | 18 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.