Threats Tagged 'cwe-476'
View all threats tagged with 'cwe-476'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-476'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-10852: CWE-476 NULL Pointer DereferenceCVE-2026-10852 0 IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the WebSphere WebServer Plug-in component when an attacker can pass crafted requests to the web server. Join the discussion | CVE Database V5 | 06/22/2026, 19:32:28 UTC Added: 06/22/2026, 19:55:50 UTC |
CVE-2026-48139: CWE-476 NULL pointer dereference in NI grpc-deviceCVE-2026-48139 0 There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of service by triggering a crash. Successful exploitation requires an attacker to provide an unknown value to the data moniker service. This affects NI grpc-device 2.17.0 and prior versions. Join the discussion | CVE Database V5 | 06/19/2026, 13:22:32 UTC Added: 06/19/2026, 14:05:57 UTC |
CVE-2026-48985: CWE-476: NULL Pointer Dereference in mcdope pam_usbCVE-2026-48985 0 pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, pusb_is_loginctl_local() can cause a NULL dereference crash when parsing loginctl output. The function calls popen() and reads the result; if the Remote field is only a newline, fgets() succeeds but strtok_r(buf, "\n", &saveptr) returns NULL. A subsequent strcmp(is_remote, "no") then dereferences NULL, causing undefined behavior (typically SIGSEGV) and crashing the PAM module. This can crash the authenticating process (e.g., sudo, login) and, depending on PAM stack configuration, deny access for all users of the affected service. This issue has been fixed in version 0.9.2. Join the discussion | CVE Database V5 | 06/18/2026, 17:30:31 UTC Added: 06/18/2026, 17:50:56 UTC |
CVE-2026-8050: CWE-476 NULL Pointer Dereference in SignalRGB SignalRGB kernel driverCVE-2026-8050 0 In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL pointer dereference, resulting in a kernel crash. Join the discussion | CVE Database V5 | 06/17/2026, 21:05:32 UTC Added: 06/17/2026, 21:50:06 UTC |
CVE-2026-1288: CWE-476 NULL Pointer Dereference in Autodesk RevitCVE-2026-1288 0 A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition. Join the discussion | CVE Database V5 | 06/17/2026, 15:27:54 UTC Added: 06/17/2026, 16:28:11 UTC |
CVE-2025-7018: CWE-476 NULL Pointer Dereference in Gen Digital Avira AntivirusCVE-2025-7018 0 Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.64. Join the discussion | CVE Database V5 | 06/12/2026, 22:13:49 UTC Added: 06/12/2026, 22:24:30 UTC |
CVE-2026-24716: CWE-476 in QNAP Systems Inc. QTSCVE-2026-24716 0 A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later Join the discussion | CVE Database V5 | 06/10/2026, 03:08:55 UTC Added: 06/10/2026, 03:40:50 UTC |
CVE-2026-22899: CWE-476 in QNAP Systems Inc. File Station 5CVE-2026-22899 0 A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later Join the discussion | CVE Database V5 | 06/10/2026, 03:07:48 UTC Added: 06/10/2026, 03:40:50 UTC |
CVE-2025-66281: CWE-476 in QNAP Systems Inc. QTSCVE-2025-66281 0 A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later Join the discussion | CVE Database V5 | 06/10/2026, 03:06:06 UTC Added: 06/10/2026, 03:40:50 UTC |
CVE-2025-62850: CWE-476 in QNAP Systems Inc. QuTS heroCVE-2025-62850 0 A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later Join the discussion | CVE Database V5 | 06/10/2026, 02:34:24 UTC Added: 06/10/2026, 03:40:50 UTC |
Showing 1 to 10 of 35 results