Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-71967MEDIUMOP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_sessionEPSS 0.2%CVE-2026-13213MEDIUMBluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects before bt_has_registerEPSS 0.2%CVE-2024-23801LOWA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < VEPSS 0.2%CVE-2022-49756MEDIUMphy: usb: sunplus: Fix potential null-ptr-deref in sp_usb_phy_probe()EPSS 0.2%CVE-2024-22043LOWA vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.251), Parasolid V35.1 (All versions < V35.1.170). The affected EPSS 0.2%CVE-2023-52371LOWVulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2024-23799LOWA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < VEPSS 0.2%CVE-2026-91780MEDIUMGNU Binutils elflink.c elf_link_add_object_symbols null pointer dereferenceEPSS 0.2%CVE-2025-21933MEDIUMarm: pgtable: fix NULL pointer dereference issueEPSS 0.2%CVE-2024-23800LOWA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < VEPSS 0.2%CVE-2026-91779MEDIUMGNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null pointer dereferenceEPSS 0.2%CVE-2024-57934MEDIUMfgraph: Add READ_ONCE() when accessing fgraph_array[]EPSS 0.2%CVE-2025-21084LOWArkcompiler Ets Runtime has an NULL pointer dereference vulnerabilityEPSS 0.2%CVE-2025-70102MEDIUMA NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (EPSS 0.2%CVE-2023-31026MEDIUMCVEEPSS 0.2%CVE-2026-90622MEDIUMGNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereferenceEPSS 0.2%CVE-2026-88339MEDIUMA NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occEPSS 0.2%CVE-2026-21300MEDIUMSubstance3D - Modeler | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2026-90609MEDIUMGPAC MP4Box vrml_tools.c null pointer dereferenceEPSS 0.2%CVE-2026-56288MEDIUMNULL Pointer Dereference in GNU patchEPSS 0.2%