Vulnerability index

Browse CVEs

26 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Traffic Server HIGH 7.5
CVE-2026-58161

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: fr…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Nimble HIGH 7.5
CVE-2026-45816

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would tr…

Fix: 1.10.0+
Fix from $1,950 2026-07-24
HTTP Server MEDIUM 5.3
CVE-2026-33007

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child p…

Fix: 2.4.67+
Fix from $1,600 2026-05-04
HTTP Server HIGH 7.5
CVE-2026-29169

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious reques…

Fix: 2.4.67+
Fix from $1,950 2026-05-04
Nimble HIGH 7.5
CVE-2025-53477

NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL p…

Fix: 1.9.0+
Fix from $1,950 2026-01-10
HTTP Server HIGH 7.5
CVE-2024-38477

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users …

Fix: 2.4.60+
Fix from $1,950 2024-07-01
HTTP Server MEDIUM 5.4
CVE-2024-36387

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, de…

Fix: after 2.4.59
Fix from $1,600 2024-07-01
HTTP Server HIGH 8.2
CVE-2021-44224EPSS 82%

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixi…

Fix: 2.4.52 / 5.20.0+
Fix from $1,950 2021-12-20
HTTP Server HIGH 7.5
CVE-2021-41524EPSS 25%

While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the …

Patch available
Fix from $1,950 2021-10-05
HTTP Server HIGH 7.5
CVE-2021-34798EPSS 65%

Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.

Fix: after 5.19.1
Fix from $1,950 2021-09-16
HTTP Server HIGH 7.5
CVE-2021-31618EPSS 51%

Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server…

Patch available
Fix from $1,950 2021-06-15
HTTP Server HIGH 7.5
CVE-2020-13950EPSS 49%

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using bot…

Fix: after 2.4.46
Fix from $1,950 2021-06-10
HTTP Server HIGH 7.5
CVE-2021-26690EPSS 65%

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, …

Fix: after 2.4.46
Fix from $1,950 2021-06-10
Subversion HIGH 7.5
CVE-2020-17525EPSS 40%

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a c…

Fix: 1.10.7 / 1.14.1+
Fix from $1,950 2021-03-17
Libapreq2 HIGH 7.5
CVE-2019-12412

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a reque…

Fix: after 2.13
Fix from $1,950 2020-11-19
Tomcat HIGH 7.5
CVE-2020-13934EPSS 64%

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after…

Fix: after 9.0.36
Fix from $1,950 2020-07-14
Nuttx CRITICAL 9.8
CVE-2020-1939

The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs…

Fix: after 8.2
Fix from $2,300 2020-05-12
Subversion HIGH 7.5
CVE-2019-0203

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain s…

Fix: after 1.11.1
Fix from $1,950 2019-09-26
HTTP Server HIGH 7.2
CVE-2019-10097EPSS 53%

In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specia…

Fix: after 17.3
Fix from $1,950 2019-09-26
HTTP Server HIGH 7.5
CVE-2018-8011EPSS 56%

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This coul…

Mitigation only
Fix from $1,950 2018-07-18
HTTP Server MEDIUM 5.9
CVE-2018-1302EPSS 13%

When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially…

Fix: after 2.4.29
Fix from $1,600 2018-03-26
Xerces C\+\+ CRITICAL 9.8
CVE-2017-12627EPSS 8%

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition…

Fix: 3.2.1+
Fix from $2,300 2018-03-01
HTTP Server HIGH 7.5
CVE-2017-7659EPSS 54%

A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the serve…

Mitigation only
Fix from $1,950 2017-07-26
HTTP Server CRITICAL 9.8
CVE-2017-3169EPSS 20%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_con…

Mitigation only
Fix from $2,300 2017-06-20
HTTP Server MEDIUM 5.0
CVE-2014-3581EPSS 14%

The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote atta…

Patch available
Fix from $1,600 2014-10-10
Subversion MEDIUM 5.0
CVE-2011-1752EPSS 8%

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of se…

Fix: 1.6.17 / 10.7.3+
Fix from $1,600 2011-06-06