Threats Tagged 'cwe-476'
View all threats tagged with 'cwe-476'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-476'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-42801 is a NULL pointer dereference vulnerability in the ASR Crane, Falcon product on Linux, specifically in the as_rrc module. This flaw allows pointer manipulation due to improper handling of NULL pointers in the program file 3g.mod/lib/src/urrsir.c. The vulnerability has a high severity rating with a CVSS score of 7.4, indicating it can impact confidentiality, integrity, and availability. No affected versions or patch information are provided, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 09/23/2026, 09:03:56 UTC Added: 09/23/2026, 09:18:15 UTC |
InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Join the discussion | CVE Database V5 | 09/22/2026, 18:33:25 UTC Added: 09/22/2026, 18:48:22 UTC |
InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Join the discussion | CVE Database V5 | 09/22/2026, 18:33:24 UTC Added: 09/22/2026, 18:48:20 UTC |
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parameters_to_set or query_parameters_to_remove from an authorization response. A path-less CONNECT request makes request_headers_->Path() return null, and Filter::onComplete dereferences that pointer while parsing the query string. An unauthenticated downstream client can crash the Envoy process when the filter and authorization response use query-parameter mutation. The relevant scope boundary is that the deployment must accept path-less CONNECT and configure ext_authz query-parameter mutation. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Join the discussion | CVE Database V5 | 09/21/2026, 19:47:54 UTC Added: 09/21/2026, 20:02:20 UTC |
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while selecting an HTTP/3 connection pool without first checking whether the pointer is null. LoadBalancerContext implementations used by synthetic, mirror, health-check, and async-client calls can return no transport-socket options. With auto_config and HTTP/3 enabled, routine traffic reaching one of those contexts can crash an Envoy worker. The relevant scope boundary is that the affected branch requires HTTP/3 in the protocol set and a context that supplies no transport-socket options. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Join the discussion | GCVE Database | 09/21/2026, 19:44:15 UTC Added: 09/17/2026, 02:00:47 UTC |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON or NDJSON dataset value_key resolves to a string. A trusted or untrusted dataset or rule feed containing a non-string value for that key can cause a NULL pointer dereference during startup, configuration test mode, or rule reload, crashing Suricata before traffic processing. This issue is fixed in version 8.0.6. Join the discussion | CVE Database V5 | 09/18/2026, 20:17:48 UTC Added: 09/18/2026, 20:32:09 UTC |
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS). Join the discussion | CVE Database V5 | 09/17/2026, 15:11:29 UTC Added: 09/17/2026, 15:32:27 UTC |
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process. Join the discussion | CVE Database V5 | 09/16/2026, 15:23:21 UTC Added: 09/16/2026, 15:32:24 UTC |
An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1. Join the discussion | CVE Database V5 | 09/16/2026, 13:55:45 UTC Added: 09/16/2026, 14:02:23 UTC |
A security flaw in GNU Binutils 2.47 affects the elf_orphan_compatible function in the ELF Orphan Section Handler, causing a null pointer dereference. Exploitation requires local access and can lead to limited confidentiality, integrity, and availability impacts. Public exploit code is available, but no vendor response or patch has been issued yet. Join the discussion | GCVE Database | 09/15/2026, 00:31:13 UTC Added: 09/15/2026, 01:37:40 UTC |
Showing 1 to 10 of 496 results