Vulnerability index

Browse CVEs

26 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
HIGH 7.5 CVE-2026-58161 Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affects Apache Traffic Server: fr… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-45816 NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would tr… Nimble 1.10.0+ Fix from $1,9502026-07-24 MEDIUM 5.3 CVE-2026-33007 A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child p… HTTP Server 2.4.67+ Fix from $1,6002026-05-04 HIGH 7.5 CVE-2026-29169 A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious reques… HTTP Server 2.4.67+ Fix from $1,9502026-05-04 HIGH 7.5 CVE-2025-53477 NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL p… Nimble 1.9.0+ Fix from $1,9502026-01-10 HIGH 7.5 CVE-2024-38477 null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users … HTTP Server 2.4.60+ Fix from $1,9502024-07-01 MEDIUM 5.4 CVE-2024-36387 Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, de… HTTP Server after 2.4.59 Fix from $1,6002024-07-01 HIGH 8.2 CVE-2021-44224EPSS 82% A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixi… HTTP Server 2.4.52 / 5.20.0+ Fix from $1,9502021-12-20 HIGH 7.5 CVE-2021-41524EPSS 25% While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the … HTTP Server Patch available Fix from $1,9502021-10-05 HIGH 7.5 CVE-2021-34798EPSS 65% Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. HTTP Server after 5.19.1 Fix from $1,9502021-09-16 HIGH 7.5 CVE-2021-31618EPSS 51% Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server… HTTP Server Patch available Fix from $1,9502021-06-15 HIGH 7.5 CVE-2020-13950EPSS 49% Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using bot… HTTP Server after 2.4.46 Fix from $1,9502021-06-10 HIGH 7.5 CVE-2021-26690EPSS 65% Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, … HTTP Server after 2.4.46 Fix from $1,9502021-06-10 HIGH 7.5 CVE-2020-17525EPSS 40% Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a c… Subversion 1.10.7 / 1.14.1+ Fix from $1,9502021-03-17 HIGH 7.5 CVE-2019-12412 A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a reque… Libapreq2 after 2.13 Fix from $1,9502020-11-19 HIGH 7.5 CVE-2020-13934EPSS 64% An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after… Tomcat after 9.0.36 Fix from $1,9502020-07-14 CRITICAL 9.8 CVE-2020-1939 The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs… Nuttx after 8.2 Fix from $2,3002020-05-12 HIGH 7.5 CVE-2019-0203 In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain s… Subversion after 1.11.1 Fix from $1,9502019-09-26 HIGH 7.2 CVE-2019-10097EPSS 53% In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specia… HTTP Server after 17.3 Fix from $1,9502019-09-26 HIGH 7.5 CVE-2018-8011EPSS 56% By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This coul… HTTP Server Mitigation only Fix from $1,9502018-07-18 MEDIUM 5.9 CVE-2018-1302EPSS 13% When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially… HTTP Server after 2.4.29 Fix from $1,6002018-03-26 CRITICAL 9.8 CVE-2017-12627EPSS 8% In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition… Xerces C\+\+ 3.2.1+ Fix from $2,3002018-03-01 HIGH 7.5 CVE-2017-7659EPSS 54% A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the serve… HTTP Server Mitigation only Fix from $1,9502017-07-26 CRITICAL 9.8 CVE-2017-3169EPSS 20% In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_con… HTTP Server Mitigation only Fix from $2,3002017-06-20 MEDIUM 5.0 CVE-2014-3581EPSS 14% The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote atta… HTTP Server Patch available Fix from $1,6002014-10-10 MEDIUM 5.0 CVE-2011-1752EPSS 8% The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of se… Subversion 1.6.17 / 10.7.3+ Fix from $1,6002011-06-06