NULL Pointer Dereference

CWE-476 · 4 records · 4 with a public proof-of-concept

Records the NVD classes as NULL Pointer Dereference (CWE-476), highest CVSS first.

  1. MEDIUM 4.9CVE-2026-76868public PoC

    Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port field to trigger the null pointer dereference, resulting in

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 4.9CVE-2026-76865public PoC

    Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An attacker can trigger the flaw by supplying crafted input to the

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-46334public PoC

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed ses

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-45084public PoC

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the presence module's handle_publish() function processes a SIP PUBLISH request with an E

    AI risk analysis on Exploit-DB.ai →