Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-65367MEDIUMA null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iEPSS 0.1%CVE-2023-53325MEDIUMdrm/mediatek: dp: Change logging to dev for mtk_dp_aux_transfer()EPSS 0.1%CVE-2023-53332MEDIUMgenirq/ipi: Fix NULL pointer deref in irq_data_get_affinity_mask()EPSS 0.1%CVE-2025-24031MEDIUMPAM-PKCS#11 vulnerable to segmentation fault on ctrl-c/ctrl-d when asked for PINEPSS 0.1%CVE-2025-60485MEDIUMA segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attaEPSS 0.1%CVE-2025-60481MEDIUMA NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackersEPSS 0.1%CVE-2023-53260MEDIUMovl: fix null pointer dereference in ovl_permission()EPSS 0.1%CVE-2025-60483MEDIUMA NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 2EPSS 0.1%CVE-2025-39903MEDIUMof_numa: fix uninitialized memory nodes causing kernel panicEPSS 0.1%CVE-2025-23332MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deferEPSS 0.1%CVE-2025-21097LOWArkcompiler Ets Runtime has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2025-25218LOWthird_party_mksh has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2025-27241LOWmultimedia_av_codec has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2026-8035MEDIUMNULL pointer dereference in NI-PALEPSS 0.1%CVE-2025-22837LOWArkcompiler Ets Runtime has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2026-6526MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2025-27248LOWai_neural_network_runtime has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2026-48066MEDIUMpam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authenticationEPSS 0.1%CVE-2026-63380MEDIUMLibevent: Null Pointer Dereference in `evws_new_session`EPSS 0.1%CVE-2026-84396MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.1%