Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-34541MEDIUMiccDEV: UB in CIccCombinedConnectionConditions::CIccCombinedConnectionConditions()EPSS 0.2%CVE-2021-37639HIGHNull pointer dereference and heap OOB read in TensorFlowEPSS 0.2%CVE-2022-20521MEDIUMIn sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing null check. This could EPSS 0.2%CVE-2021-41208HIGHIncomplete validation in boosted trees codeEPSS 0.2%CVE-2024-57914MEDIUMusb: typec: tcpci: fix NULL pointer issue on shared irq caseEPSS 0.2%CVE-2021-37681HIGHNull pointer exception in TensorFlow LiteEPSS 0.2%CVE-2026-33996MEDIUMLibJWT has NULL/bounds validation in JWK octet and RSA PSS parsingEPSS 0.2%CVE-2024-57927MEDIUMnfs: Fix oops in nfs_netfs_init_request() when copying to cacheEPSS 0.2%CVE-2024-57944MEDIUMiio: adc: ti-ads1298: Add NULL check in ads1298_initEPSS 0.2%CVE-2024-56612MEDIUMmm/gup: handle NULL pages in unpin_user_pages()EPSS 0.2%CVE-2025-21953MEDIUMnet: mana: cleanup mana struct after debugfs_remove()EPSS 0.2%CVE-2026-90829MEDIUMGNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereferenceEPSS 0.2%CVE-2024-24856MEDIUMNULL pointer deference in acpi_db_convert_to_package of Linux acpi moduleEPSS 0.2%CVE-2025-0121MEDIUMCortex XDR Agent: Local Windows User Can Crash the AgentEPSS 0.2%CVE-2022-50405HIGHnet/tunnel: wait until all sk_user_data reader finish before releasing the sockEPSS 0.2%CVE-2026-5745MEDIUMLibarchive: a null pointer dereference vulnerability exists in the acl parser of libarchiveEPSS 0.2%CVE-2024-56540HIGHaccel/ivpu: Prevent recovery invocation during probe and resumeEPSS 0.2%CVE-2023-31021MEDIUMCVEEPSS 0.2%CVE-2023-0197MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereEPSS 0.2%CVE-2026-91779MEDIUMGNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null pointer dereferenceEPSS 0.2%