Vulnerability index

Browse CVEs

5,204 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
MEDIUM 5.5 CVE-2025-38543 In the Linux kernel, the following vulnerability has been resolved: drm/tegra: nvdec: Fix dma_alloc_coherent error check Check for NULL return valu… Linux Kernel 6.1.146 / 6.6.99+ Fix from $1,6002025-08-16 MEDIUM 5.5 CVE-2025-38541 In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init() devm_kasprintf(… Linux Kernel 6.12.39 / 6.15.7+ Fix from $1,6002025-08-16 MEDIUM 5.5 CVE-2025-38526 In the Linux kernel, the following vulnerability has been resolved: ice: add NULL check in eswitch lag check The function ice_lag_is_switchdev_runn… Linux Kernel 6.6.100 / 6.12.40+ Fix from $1,6002025-08-16 MEDIUM 5.5 CVE-2025-38522 In the Linux kernel, the following vulnerability has been resolved: sched/ext: Prevent update_locked_rq() calls with NULL rq Avoid invoking update_… Linux Kernel 6.15.8+ Fix from $1,6002025-08-16 MEDIUM 5.5 CVE-2025-38510 In the Linux kernel, the following vulnerability has been resolved: kasan: remove kasan_find_vm_area() to prevent possible deadlock find_vm_area() … Linux Kernel 6.1.146 / 6.6.99+ Fix from $1,6002025-08-16 MEDIUM 5.5 CVE-2025-38513 In the Linux kernel, the following vulnerability has been resolved: wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() Th… Linux Kernel 5.4.296 / 5.10.240+ Fix from $1,6002025-08-16 MEDIUM 5.5 CVE-2025-38516 In the Linux kernel, the following vulnerability has been resolved: pinctrl: qcom: msm: mark certain pins as invalid for interrupts On some platfor… Linux Kernel 5.4.296 / 5.10.240+ Fix from $1,6002025-08-16 MEDIUM 5.5 CVE-2025-38517 In the Linux kernel, the following vulnerability has been resolved: lib/alloc_tag: do not acquire non-existent lock in alloc_tag_top_users() alloc_… Linux Kernel 6.12.39 / 6.15.7+ Fix from $1,6002025-08-16 HIGH 7.5 CVE-2025-54989 Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-ser… Firebird 3.0.13 / 4.0.6+ Fix from $1,9502025-08-15 MEDIUM 5.5 CVE-2025-54409 AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An atta… Advanced Intrusion Detection Environment 0.19.2+ Fix from $1,6002025-08-14 HIGH 7.5 CVE-2025-52585 When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enab… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6+ Fix from $1,9502025-08-13 HIGH 7.5 CVE-2025-50635 A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function of the cgit… Wf2780 Firmware No fix yet Fix from $1,9502025-08-13 HIGH 7.8 CVE-2025-53154 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 MEDIUM 6.5 CVE-2025-53716 Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. Windows 10 1809 10.0.17763.7678 / 10.0.19044.6216+ Fix from $1,6002025-08-12 HIGH 7.8 CVE-2025-53141 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 MEDIUM 5.5 CVE-2025-49567 Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-ser… Illustrator 28.7.9 / 29.7+ Fix from $1,6002025-08-12 MEDIUM 6.5 CVE-2025-24515 NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access. Mitigation only Fix from $1,6002025-08-12 MEDIUM 5.5 CVE-2025-8844 A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c.… Netwide Assembler No fix yet Fix from $1,6002025-08-11 MEDIUM 5.5 CVE-2025-8835 A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas… Jasper after 4.2.5 Fix from $1,6002025-08-11 MEDIUM 5.5 CVE-2025-26690 in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. Openharmony after 5.0.3 Fix from $1,6002025-08-11 MEDIUM 5.5 CVE-2025-47807 In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, … Gstreamer 1.26.2+ Fix from $1,6002025-08-07 MEDIUM 5.6 CVE-2025-47808 In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading… Gstreamer 1.26.2+ Fix from $1,6002025-08-07 MEDIUM 6.5 CVE-2025-50952 openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c. Openjpeg Mitigation only Fix from $1,6002025-08-07 HIGH 7.5 CVE-2025-41691 An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafte… Mitigation only Fix from $1,9502025-08-04 HIGH 7.5 CVE-2025-53010 MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, wh… Materialx Patch available Fix from $1,9502025-08-01 HIGH 7.5 CVE-2025-53011 MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, wh… Materialx Patch available Fix from $1,9502025-08-01 MEDIUM 6.5 CVE-2025-49832 Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, between 20.00.0 and 20.15.0, 20.7-… Asterisk 18.26.3 / 20.15.1+ Fix from $1,6002025-08-01 MEDIUM 6.7 CVE-2025-6398 A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a specially craft… Mitigation only Fix from $1,6002025-08-01 MEDIUM 6.2 CVE-2025-48073 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In v… Openexr No fix yet Fix from $1,6002025-07-31 MEDIUM 5.5 CVE-2025-38487 In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled Mitigate e.g… Linux Kernel 5.4.297 / 5.10.241+ Fix from $1,6002025-07-28