The product dereferences a pointer that it expects to be valid but is NULL.
Volume of CVEs assigned to CWE-476 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
5,444 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1386MEDIUM ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occur | Jun 4, 2009 | 5.0 | 77 | NO | YES |
CVE-2006-6565MEDIUM FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL po | Dec 15, 2006 | 4.0 | 77 | NO | YES |
CVE-2023-21758HIGH Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | Jan 10, 2023 | 7.5 | 75 | NO | NO |
CVE-2023-21547HIGH Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | Jan 10, 2023 | 7.5 | 72 | NO | NO |
CVE-2021-44224HIGH A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy de | Dec 20, 2021 | 8.2 | 72 | NO | NO |
CVE-2016-0742HIGH The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted | Feb 15, 2016 | 7.5 | 70 | NO | NO |
CVE-2026-21525MEDIUM Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. | Feb 10, 2026 | 6.2 | 67 | YES | NO |
CVE-2017-3730HIGH In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL po | May 4, 2017 | 7.5 | 67 | NO | YES |
CVE-2018-8011HIGH By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fi | Jul 18, 2018 | 7.5 | 64 | NO | YES |
CVE-2021-34798HIGH Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 7.5 | 61 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.