Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-17574MEDIUMNULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type TagEPSS 0.1%CVE-2026-3776MEDIUMNull pointer dereference in Foxit PDF Editor/Reader when accessing stamp annotationEPSS 0.1%CVE-2026-82926MEDIUMNULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aEPSS 0.1%CVE-2025-20676MEDIUMIn wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execEPSS 0.1%CVE-2026-42442LOWNanaZip: Null-pointer dereference in NanaZip UFS parser when root inode is a symlinkEPSS 0.1%CVE-2025-20675MEDIUMIn wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execEPSS 0.1%CVE-2025-23300MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocaEPSS 0.1%CVE-2025-10823MEDIUMaxboe fio options.c str_buffer_pattern_cb null pointer dereferenceEPSS 0.1%CVE-2025-60007MEDIUMJunos OS: A specifically crafted 'show chassis' command causes chassisd to crashEPSS 0.1%CVE-2025-45525LOWA NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a lightweight syntax highliEPSS 0.1%CVE-2023-53292MEDIUMblk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_noneEPSS 0.1%CVE-2025-39895MEDIUMsched: Fix sched_numa_find_nth_cpu() if mask offlineEPSS 0.1%CVE-2026-24805MEDIUMMishandles certain out-of-memory conditions in visualfc/liteide via liteidex/src/3rdparty/libvterm/src moduleEPSS 0.1%CVE-2026-6845MEDIUMBinutils: binutils: denial of service via crafted elf fileEPSS 0.1%CVE-2023-53244MEDIUMmedia: pci: tw68: Fix null-ptr-deref bug in buf prepare and finishEPSS 0.1%CVE-2025-6966MEDIUMNull-pointer dereference in python-apt TagSection.keys()EPSS 0.1%CVE-2023-53251MEDIUMwifi: iwlwifi: pcie: fix NULL pointer dereference in iwl_pcie_irq_rx_msix_handler()EPSS 0.1%CVE-2025-62815MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.astEPSS 0.1%CVE-2023-53389MEDIUMdrm/mediatek: dp: Only trigger DRM HPD events if bridge is attachedEPSS 0.1%CVE-2023-53326MEDIUMpowerpc: Don't try to copy PPR for task with NULL pt_regsEPSS 0.1%