Vulnerability index

Browse CVEs

5,204 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Linux Kernel MEDIUM 5.5
CVE-2025-38543

In the Linux kernel, the following vulnerability has been resolved: drm/tegra: nvdec: Fix dma_alloc_coherent error check Check for NULL return valu…

Fix: 6.1.146 / 6.6.99+
Fix from $1,600 2025-08-16
Linux Kernel MEDIUM 5.5
CVE-2025-38541

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init() devm_kasprintf(…

Fix: 6.12.39 / 6.15.7+
Fix from $1,600 2025-08-16
Linux Kernel MEDIUM 5.5
CVE-2025-38526

In the Linux kernel, the following vulnerability has been resolved: ice: add NULL check in eswitch lag check The function ice_lag_is_switchdev_runn…

Fix: 6.6.100 / 6.12.40+
Fix from $1,600 2025-08-16
Linux Kernel MEDIUM 5.5
CVE-2025-38522

In the Linux kernel, the following vulnerability has been resolved: sched/ext: Prevent update_locked_rq() calls with NULL rq Avoid invoking update_…

Fix: 6.15.8+
Fix from $1,600 2025-08-16
Linux Kernel MEDIUM 5.5
CVE-2025-38510

In the Linux kernel, the following vulnerability has been resolved: kasan: remove kasan_find_vm_area() to prevent possible deadlock find_vm_area() …

Fix: 6.1.146 / 6.6.99+
Fix from $1,600 2025-08-16
Linux Kernel MEDIUM 5.5
CVE-2025-38513

In the Linux kernel, the following vulnerability has been resolved: wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() Th…

Fix: 5.4.296 / 5.10.240+
Fix from $1,600 2025-08-16
Linux Kernel MEDIUM 5.5
CVE-2025-38516

In the Linux kernel, the following vulnerability has been resolved: pinctrl: qcom: msm: mark certain pins as invalid for interrupts On some platfor…

Fix: 5.4.296 / 5.10.240+
Fix from $1,600 2025-08-16
Linux Kernel MEDIUM 5.5
CVE-2025-38517

In the Linux kernel, the following vulnerability has been resolved: lib/alloc_tag: do not acquire non-existent lock in alloc_tag_top_users() alloc_…

Fix: 6.12.39 / 6.15.7+
Fix from $1,600 2025-08-16
Firebird HIGH 7.5
CVE-2025-54989

Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-ser…

Fix: 3.0.13 / 4.0.6+
Fix from $1,950 2025-08-15
Advanced Intrusion Detection Environment MEDIUM 5.5
CVE-2025-54409

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An atta…

Fix: 0.19.2+
Fix from $1,600 2025-08-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-52585

When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enab…

Fix: 15.1.10.8 / 16.1.6+
Fix from $1,950 2025-08-13
Wf2780 Firmware HIGH 7.5
CVE-2025-50635

A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function of the cgit…

No fix yet
Fix from $1,950 2025-08-13
Windows 10 1507 HIGH 7.8
CVE-2025-53154

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Windows 10 1809 MEDIUM 6.5
CVE-2025-53716

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

Fix: 10.0.17763.7678 / 10.0.19044.6216+
Fix from $1,600 2025-08-12
Windows 10 1507 HIGH 7.8
CVE-2025-53141

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Illustrator MEDIUM 5.5
CVE-2025-49567

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-ser…

Fix: 28.7.9 / 29.7+
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.5
CVE-2025-24515

NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.

Mitigation only
Fix from $1,600 2025-08-12
Netwide Assembler MEDIUM 5.5
CVE-2025-8844

A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c.…

No fix yet
Fix from $1,600 2025-08-11
Jasper MEDIUM 5.5
CVE-2025-8835

A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas…

Fix: after 4.2.5
Fix from $1,600 2025-08-11
Openharmony MEDIUM 5.5
CVE-2025-26690

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

Fix: after 5.0.3
Fix from $1,600 2025-08-11
Gstreamer MEDIUM 5.5
CVE-2025-47807

In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, …

Fix: 1.26.2+
Fix from $1,600 2025-08-07
Gstreamer MEDIUM 5.6
CVE-2025-47808

In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading…

Fix: 1.26.2+
Fix from $1,600 2025-08-07
Openjpeg MEDIUM 6.5
CVE-2025-50952

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

Mitigation only
Fix from $1,600 2025-08-07
Unclassified HIGH 7.5
CVE-2025-41691

An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafte…

Mitigation only
Fix from $1,950 2025-08-04
Materialx HIGH 7.5
CVE-2025-53010

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, wh…

Patch available
Fix from $1,950 2025-08-01
Materialx HIGH 7.5
CVE-2025-53011

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, wh…

Patch available
Fix from $1,950 2025-08-01
Asterisk MEDIUM 6.5
CVE-2025-49832

Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, between 20.00.0 and 20.15.0, 20.7-…

Fix: 18.26.3 / 20.15.1+
Fix from $1,600 2025-08-01
Unclassified MEDIUM 6.7
CVE-2025-6398

A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a specially craft…

Mitigation only
Fix from $1,600 2025-08-01
Openexr MEDIUM 6.2
CVE-2025-48073

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In v…

No fix yet
Fix from $1,600 2025-07-31
Linux Kernel MEDIUM 5.5
CVE-2025-38487

In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled Mitigate e.g…

Fix: 5.4.297 / 5.10.241+
Fix from $1,600 2025-07-28