CWE-476 · 5 304 записей
NULL Pointer Dereference
CVE этого класса
5 309 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2023-21758Эксплойта нет | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerabilitymicrosoft · windows 10 · CWE-476 | Высокая7,5 | — | 92,5 % | 10 янв. 2023 г. |
57В плане | CVE-2023-21547Эксплойта нет | Internet Key Exchange (IKE) Protocol Denial of Service Vulnerabilitymicrosoft · windows 10 1607 · CWE-476 | Высокая7,5 | — | 89,3 % | 10 янв. 2023 г. |
57В плане | CVE-2021-44224Эксплойта нет | Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlierapache · http server · CWE-476 | Высокая8,2 | — | 82,3 % | 20 дек. 2021 г. |
55В плане | CVE-2016-0742Эксплойта нет | The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereferencef5 · nginx · CWE-476 | Высокая7,5 | — | 82,4 % | 15 февр. 2016 г. |
55В плане | CVE-2026-21525Готовый эксплойт | Windows Remote Access Connection Manager Denial of Service Vulnerabilitymicrosoft · windows 10 1607 · CWE-476 | Средняя6,2 | KEV | 4,8 % | 10 февр. 2026 г. |
51В плане | CVE-2023-38171Эксплойта нет | Microsoft QUIC Denial of Service Vulnerabilitymicrosoft · .net · CWE-476 | Высокая7,5 | — | 69,7 % | 10 окт. 2023 г. |
50В плане | CVE-2021-26690Proof of concept | mod_session NULL pointer dereferenceapache · http server · CWE-476 | Высокая7,5 | — | 65,3 % | 10 июн. 2021 г. |
49В плане | CVE-2021-34798Эксплойта нет | NULL pointer dereference in httpd coreapache · http server · CWE-476 | Высокая7,5 | — | 64,5 % | 16 сент. 2021 г. |
47В плане | CVE-2025-21285Эксплойта нет | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerabilitymicrosoft · windows 10 1507 · CWE-476 | Высокая7,5 | — | 55,7 % | 14 янв. 2025 г. |
47В плане | CVE-2018-8011Proof of concept | mod_md, DoS via Coredumps on specially crafted requestsapache · http server · CWE-476 | Высокая7,5 | — | 55,6 % | 18 июл. 2018 г. |
47В плане | CVE-2017-3730Proof of concept | Bad (EC)DHE parameters cause a client crashopenssl · openssl · CWE-476 | Высокая7,5 | — | 55,3 % | 4 мая 2017 г. |
46В плане | CVE-2004-0389Proof of concept | RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests thatrealnetworks · helix universal server · CWE-476 | Высокая7,5 | — | 54,9 % | 1 июн. 2004 г. |
46В плане | CVE-2017-7659Эксплойта нет | A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash apache · http server · CWE-476 | Высокая7,5 | — | 53,9 % | 26 июл. 2017 г. |
46В плане | CVE-2020-1967Proof of concept | Segmentation fault in SSL_check_chainopenssl · openssl · CWE-476 | Высокая7,5 | — | 53,3 % | 21 апр. 2020 г. |
46В плане | CVE-2017-15120Proof of concept | An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference whepowerdns · recursor · CWE-476 | Высокая7,5 | — | 51,8 % | 27 июл. 2018 г. |
45В плане | CVE-2021-31618Эксплойта нет | NULL pointer dereference on specially crafted HTTP/2 requestapache · http server · CWE-476 | Высокая7,5 | — | 51,5 % | 15 июн. 2021 г. |
45В плане | CVE-2020-13950Эксплойта нет | mod_proxy_http NULL pointer dereferenceapache · http server · CWE-476 | Высокая7,5 | — | 49,4 % | 10 июн. 2021 г. |
45В плане | CVE-2017-3169Эксплойта нет | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_prapache · http server · CWE-476 | Критическая9,8 | — | 20,0 % | 19 июн. 2017 г. |
44В плане | CVE-2009-1386Готовый эксплойт | ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via aopenssl · openssl · CWE-476 | Средняя5,0 | — | 80,1 % | 4 июн. 2009 г. |
44В плане | CVE-2019-10097Эксплойта нет | In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol,apache · http server · CWE-476 | Высокая7,2 | — | 52,9 % | 26 сент. 2019 г. |
44В плане | CVE-2007-0039Эксплойта нет | The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remotmicrosoft · exchange server · CWE-476 | Высокая7,8 | — | 44,6 % | 8 мая 2007 г. |
43В плане | CVE-2014-3470Эксплойта нет | The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anoopenssl · openssl · CWE-476 | Средняя4,3 | — | 85,8 % | 5 июн. 2014 г. |
43В плане | CVE-2025-22037Эксплойта нет | ksmbd: fix null pointer dereference in alloc_preauth_hash()linux · linux kernel · CWE-476 | Средняя5,5 | — | 69,6 % | 16 апр. 2025 г. |
43В плане | CVE-2016-4957Эксплойта нет | ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet.ntp · ntp · CWE-476 | Высокая7,5 | — | 44,9 % | 4 июл. 2016 г. |
43В плане | CVE-2015-3194Proof of concept | crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL poiopenssl · openssl · CWE-476 | Высокая7,5 | — | 44,0 % | 6 дек. 2015 г. |
- CVE-2023-2175858В плане
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 93 %microsoft · windows 1010 янв. 2023 г.
- CVE-2023-2154757В плане
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 89 %microsoft · windows 10 160710 янв. 2023 г.
- CVE-2021-4422457В плане
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
ВысокаяCVSS 8,2Эксплойта нетEPSS 82 %apache · http server20 дек. 2021 г.
- CVE-2016-074255В плане
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference
ВысокаяCVSS 7,5Эксплойта нетEPSS 82 %f5 · nginx15 февр. 2016 г.
- CVE-2026-2152555В плане
Windows Remote Access Connection Manager Denial of Service Vulnerability
СредняяCVSS 6,2KEVГотовый эксплойтEPSS 5 %microsoft · windows 10 160710 февр. 2026 г.
- CVE-2023-3817151В плане
Microsoft QUIC Denial of Service Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 70 %microsoft · .net10 окт. 2023 г.
- CVE-2021-2669050В плане
mod_session NULL pointer dereference
ВысокаяCVSS 7,5Proof of conceptEPSS 65 %apache · http server10 июн. 2021 г.
- CVE-2021-3479849В плане
NULL pointer dereference in httpd core
ВысокаяCVSS 7,5Эксплойта нетEPSS 65 %apache · http server16 сент. 2021 г.
- CVE-2025-2128547В плане
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 56 %microsoft · windows 10 150714 янв. 2025 г.
- CVE-2018-801147В плане
mod_md, DoS via Coredumps on specially crafted requests
ВысокаяCVSS 7,5Proof of conceptEPSS 56 %apache · http server18 июл. 2018 г.
- CVE-2017-373047В плане
Bad (EC)DHE parameters cause a client crash
ВысокаяCVSS 7,5Proof of conceptEPSS 55 %openssl · openssl4 мая 2017 г.
- CVE-2004-038946В плане
RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that
ВысокаяCVSS 7,5Proof of conceptEPSS 55 %realnetworks · helix universal server1 июн. 2004 г.
- CVE-2017-765946В плане
A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash
ВысокаяCVSS 7,5Эксплойта нетEPSS 54 %apache · http server26 июл. 2017 г.
- CVE-2020-196746В плане
Segmentation fault in SSL_check_chain
ВысокаяCVSS 7,5Proof of conceptEPSS 53 %openssl · openssl21 апр. 2020 г.
- CVE-2017-1512046В плане
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference whe
ВысокаяCVSS 7,5Proof of conceptEPSS 52 %powerdns · recursor27 июл. 2018 г.
- CVE-2021-3161845В плане
NULL pointer dereference on specially crafted HTTP/2 request
ВысокаяCVSS 7,5Эксплойта нетEPSS 51 %apache · http server15 июн. 2021 г.
- CVE-2020-1395045В плане
mod_proxy_http NULL pointer dereference
ВысокаяCVSS 7,5Эксплойта нетEPSS 49 %apache · http server10 июн. 2021 г.
- CVE-2017-316945В плане
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_pr
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %apache · http server19 июн. 2017 г.
- CVE-2009-138644В плане
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a
СредняяCVSS 5,0Готовый эксплойтEPSS 80 %openssl · openssl4 июн. 2009 г.
- CVE-2019-1009744В плане
In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol,
ВысокаяCVSS 7,2Эксплойта нетEPSS 53 %apache · http server26 сент. 2019 г.
- CVE-2007-003944В плане
The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remot
ВысокаяCVSS 7,8Эксплойта нетEPSS 45 %microsoft · exchange server8 мая 2007 г.
- CVE-2014-347043В плане
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an ano
СредняяCVSS 4,3Эксплойта нетEPSS 86 %openssl · openssl5 июн. 2014 г.
- CVE-2025-2203743В плане
ksmbd: fix null pointer dereference in alloc_preauth_hash()
СредняяCVSS 5,5Эксплойта нетEPSS 70 %linux · linux kernel16 апр. 2025 г.
- CVE-2016-495743В плане
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet.
ВысокаяCVSS 7,5Эксплойта нетEPSS 45 %ntp · ntp4 июл. 2016 г.
- CVE-2015-319443В плане
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL poi
ВысокаяCVSS 7,5Proof of conceptEPSS 44 %openssl · openssl6 дек. 2015 г.