CWE-476 · 5,304 records
NULL Pointer Dereference
CVEs in this class
5,309 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2023-21758No exploit | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerabilitymicrosoft · windows 10 · CWE-476 | High7.5 | — | 92.5% | Jan 10, 2023 |
57Plan | CVE-2023-21547No exploit | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerabilitymicrosoft · windows 10 1607 · CWE-476 | High7.5 | — | 89.3% | Jan 10, 2023 |
57Plan | CVE-2021-44224No exploit | Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlierapache · http server · CWE-476 | High8.2 | — | 82.3% | Dec 20, 2021 |
55Plan | CVE-2016-0742No exploit | The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereferencef5 · nginx · CWE-476 | High7.5 | — | 82.4% | Feb 15, 2016 |
55Plan | CVE-2026-21525Weaponized | Windows Remote Access Connection Manager Denial of Service Vulnerabilitymicrosoft · windows 10 1607 · CWE-476 | Medium6.2 | KEV | 4.8% | Feb 10, 2026 |
51Plan | CVE-2023-38171No exploit | Microsoft QUIC Denial of Service Vulnerabilitymicrosoft · .net · CWE-476 | High7.5 | — | 69.7% | Oct 10, 2023 |
50Plan | CVE-2021-26690Proof of concept | mod_session NULL pointer dereferenceapache · http server · CWE-476 | High7.5 | — | 65.3% | Jun 10, 2021 |
49Plan | CVE-2021-34798No exploit | NULL pointer dereference in httpd coreapache · http server · CWE-476 | High7.5 | — | 64.5% | Sep 16, 2021 |
47Plan | CVE-2025-21285No exploit | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerabilitymicrosoft · windows 10 1507 · CWE-476 | High7.5 | — | 55.7% | Jan 14, 2025 |
47Plan | CVE-2018-8011Proof of concept | mod_md, DoS via Coredumps on specially crafted requestsapache · http server · CWE-476 | High7.5 | — | 55.6% | Jul 18, 2018 |
47Plan | CVE-2017-3730Proof of concept | Bad (EC)DHE parameters cause a client crashopenssl · openssl · CWE-476 | High7.5 | — | 55.3% | May 4, 2017 |
46Plan | CVE-2004-0389Proof of concept | RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests thatrealnetworks · helix universal server · CWE-476 | High7.5 | — | 54.9% | Jun 1, 2004 |
46Plan | CVE-2017-7659No exploit | A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash apache · http server · CWE-476 | High7.5 | — | 53.9% | Jul 26, 2017 |
46Plan | CVE-2020-1967Proof of concept | Segmentation fault in SSL_check_chainopenssl · openssl · CWE-476 | High7.5 | — | 53.3% | Apr 21, 2020 |
46Plan | CVE-2017-15120Proof of concept | An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference whepowerdns · recursor · CWE-476 | High7.5 | — | 51.8% | Jul 27, 2018 |
45Plan | CVE-2021-31618No exploit | NULL pointer dereference on specially crafted HTTP/2 requestapache · http server · CWE-476 | High7.5 | — | 51.5% | Jun 15, 2021 |
45Plan | CVE-2020-13950No exploit | mod_proxy_http NULL pointer dereferenceapache · http server · CWE-476 | High7.5 | — | 49.4% | Jun 10, 2021 |
45Plan | CVE-2017-3169No exploit | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_prapache · http server · CWE-476 | Critical9.8 | — | 20.0% | Jun 19, 2017 |
44Plan | CVE-2009-1386Weaponized | ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via aopenssl · openssl · CWE-476 | Medium5.0 | — | 80.1% | Jun 4, 2009 |
44Plan | CVE-2019-10097No exploit | In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol,apache · http server · CWE-476 | High7.2 | — | 52.9% | Sep 26, 2019 |
44Plan | CVE-2007-0039No exploit | The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remotmicrosoft · exchange server · CWE-476 | High7.8 | — | 44.6% | May 8, 2007 |
43Plan | CVE-2014-3470No exploit | The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anoopenssl · openssl · CWE-476 | Medium4.3 | — | 85.8% | Jun 5, 2014 |
43Plan | CVE-2025-22037No exploit | ksmbd: fix null pointer dereference in alloc_preauth_hash()linux · linux kernel · CWE-476 | Medium5.5 | — | 69.6% | Apr 16, 2025 |
43Plan | CVE-2016-4957No exploit | ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet.ntp · ntp · CWE-476 | High7.5 | — | 44.9% | Jul 4, 2016 |
43Plan | CVE-2015-3194Proof of concept | crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL poiopenssl · openssl · CWE-476 | High7.5 | — | 44.0% | Dec 6, 2015 |
- CVE-2023-2175858Plan
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
HighCVSS 7.5No exploitEPSS 93%microsoft · windows 10Jan 10, 2023
- CVE-2023-2154757Plan
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
HighCVSS 7.5No exploitEPSS 89%microsoft · windows 10 1607Jan 10, 2023
- CVE-2021-4422457Plan
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
HighCVSS 8.2No exploitEPSS 82%apache · http serverDec 20, 2021
- CVE-2016-074255Plan
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference
HighCVSS 7.5No exploitEPSS 82%f5 · nginxFeb 15, 2016
- CVE-2026-2152555Plan
Windows Remote Access Connection Manager Denial of Service Vulnerability
MediumCVSS 6.2KEVWeaponizedEPSS 5%microsoft · windows 10 1607Feb 10, 2026
- CVE-2023-3817151Plan
Microsoft QUIC Denial of Service Vulnerability
HighCVSS 7.5No exploitEPSS 70%microsoft · .netOct 10, 2023
- CVE-2021-2669050Plan
mod_session NULL pointer dereference
HighCVSS 7.5Proof of conceptEPSS 65%apache · http serverJun 10, 2021
- CVE-2021-3479849Plan
NULL pointer dereference in httpd core
HighCVSS 7.5No exploitEPSS 65%apache · http serverSep 16, 2021
- CVE-2025-2128547Plan
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
HighCVSS 7.5No exploitEPSS 56%microsoft · windows 10 1507Jan 14, 2025
- CVE-2018-801147Plan
mod_md, DoS via Coredumps on specially crafted requests
HighCVSS 7.5Proof of conceptEPSS 56%apache · http serverJul 18, 2018
- CVE-2017-373047Plan
Bad (EC)DHE parameters cause a client crash
HighCVSS 7.5Proof of conceptEPSS 55%openssl · opensslMay 4, 2017
- CVE-2004-038946Plan
RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that
HighCVSS 7.5Proof of conceptEPSS 55%realnetworks · helix universal serverJun 1, 2004
- CVE-2017-765946Plan
A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash
HighCVSS 7.5No exploitEPSS 54%apache · http serverJul 26, 2017
- CVE-2020-196746Plan
Segmentation fault in SSL_check_chain
HighCVSS 7.5Proof of conceptEPSS 53%openssl · opensslApr 21, 2020
- CVE-2017-1512046Plan
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference whe
HighCVSS 7.5Proof of conceptEPSS 52%powerdns · recursorJul 27, 2018
- CVE-2021-3161845Plan
NULL pointer dereference on specially crafted HTTP/2 request
HighCVSS 7.5No exploitEPSS 51%apache · http serverJun 15, 2021
- CVE-2020-1395045Plan
mod_proxy_http NULL pointer dereference
HighCVSS 7.5No exploitEPSS 49%apache · http serverJun 10, 2021
- CVE-2017-316945Plan
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_pr
CriticalCVSS 9.8No exploitEPSS 20%apache · http serverJun 19, 2017
- CVE-2009-138644Plan
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a
MediumCVSS 5.0WeaponizedEPSS 80%openssl · opensslJun 4, 2009
- CVE-2019-1009744Plan
In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol,
HighCVSS 7.2No exploitEPSS 53%apache · http serverSep 26, 2019
- CVE-2007-003944Plan
The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remot
HighCVSS 7.8No exploitEPSS 45%microsoft · exchange serverMay 8, 2007
- CVE-2014-347043Plan
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an ano
MediumCVSS 4.3No exploitEPSS 86%openssl · opensslJun 5, 2014
- CVE-2025-2203743Plan
ksmbd: fix null pointer dereference in alloc_preauth_hash()
MediumCVSS 5.5No exploitEPSS 70%linux · linux kernelApr 16, 2025
- CVE-2016-495743Plan
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet.
HighCVSS 7.5No exploitEPSS 45%ntp · ntpJul 4, 2016
- CVE-2015-319443Plan
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL poi
HighCVSS 7.5Proof of conceptEPSS 44%openssl · opensslDec 6, 2015