Weaknesses of type CWE-476

2,334 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2021-37688HIGHNull pointer dereference in TensorFlow LiteEPSS 0.2%CVE-2025-33197MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereference. A successful expEPSS 0.2%CVE-2024-45476MEDIUMA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2026-21901MEDIUMJunos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crashEPSS 0.2%CVE-2025-20673MEDIUMIn wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execEPSS 0.2%CVE-2026-48985MEDIUMpam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remote FieldEPSS 0.2%CVE-2025-20677MEDIUMIn Bluetooth driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User exeEPSS 0.2%CVE-2025-15571MEDIUMckolivas lrzip stream.c ucompthread null pointer dereferenceEPSS 0.2%CVE-2026-1990MEDIUMoatpp Type.hpp ObjectWrapper null pointer dereferenceEPSS 0.2%CVE-2022-49895MEDIUMcxl/region: Fix decoder allocation crashEPSS 0.2%CVE-2022-49894MEDIUMcxl/region: Fix region HPA ordering validationEPSS 0.2%CVE-2025-6496MEDIUMHTACG tidy-html5 parser.c InsertNodeAsParent null pointer dereferenceEPSS 0.2%CVE-2024-35215MEDIUMNULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 aEPSS 0.2%CVE-2023-53364MEDIUMregulator: da9063: better fix null deref with partial DTEPSS 0.2%CVE-2022-49848MEDIUMphy: qcom-qmp-combo: fix NULL-deref on runtime resumeEPSS 0.2%CVE-2022-50415MEDIUMparisc: led: Fix potential null-ptr-deref in start_task()EPSS 0.2%CVE-2022-49876MEDIUMwifi: mac80211: fix general-protection-fault in ieee80211_subif_start_xmit()EPSS 0.2%CVE-2024-31078LOWBluetooth Service has a use after free vulnerabilityEPSS 0.2%CVE-2026-7450MEDIUMPAR File Parsing NULL Pointer Dereference in Autodesk 3ds MaxEPSS 0.2%CVE-2026-86056MEDIUMNotepad++: Null pointer dereference in NPPM_SAVESESSION message handler causes crash (DoS)EPSS 0.2%