Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-88339MEDIUMA NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occEPSS 0.2%CVE-2026-90622MEDIUMGNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereferenceEPSS 0.2%CVE-2026-19024HIGHHDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value MessageEPSS 0.2%CVE-2026-56288MEDIUMNULL Pointer Dereference in GNU patchEPSS 0.2%CVE-2026-90576MEDIUMGPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereferenceEPSS 0.2%CVE-2026-21300MEDIUMSubstance3D - Modeler | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2026-21301MEDIUMSubstance3D - Modeler | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2026-76781MEDIUMLibxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attributeEPSS 0.2%CVE-2026-33179MEDIUMlibfuse: NULL Pointer Dereference and Memory Leak in io_uring Queue InitializationEPSS 0.2%CVE-2021-37638HIGHNull pointer dereference in `RaggedTensorToTensor` in TensorFlowEPSS 0.2%CVE-2026-55371MEDIUMOpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_lengthEPSS 0.2%CVE-2026-2642MEDIUMggreer the_silver_searcher search.c search_stream null pointer dereferenceEPSS 0.2%CVE-2023-0973LOWStep Tools Third-PartyEPSS 0.2%CVE-2026-90485MEDIUMIOBit Uninstaller IOCTL Dispatch IURegistryFilter.sys sub_11838 null pointer dereferenceEPSS 0.2%CVE-2026-80118HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTLEPSS 0.2%CVE-2026-2903MEDIUMskvadrik re2c ast.cc check_and_merge_special_rules null pointer dereferenceEPSS 0.2%CVE-2026-21901MEDIUMJunos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crashEPSS 0.2%CVE-2021-37688HIGHNull pointer dereference in TensorFlow LiteEPSS 0.2%CVE-2024-45476MEDIUMA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2025-33197MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereference. A successful expEPSS 0.2%