Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-6525MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2024-5198LOWOpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driveEPSS 0.1%CVE-2025-21998MEDIUMfirmware: qcom: uefisecapp: fix efivars registration raceEPSS 0.1%CVE-2025-15535MEDIUMnicbarker clay clay.h Clay__MeasureTextCached null pointer dereferenceEPSS 0.1%CVE-2026-76881MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2025-14841MEDIUMOFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereferenceEPSS 0.1%CVE-2023-53401MEDIUMmm: kmem: fix a NULL pointer dereference in obj_stock_flush_required()EPSS 0.1%CVE-2024-9484MEDIUMAn null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformEPSS 0.1%CVE-2025-39906HIGHdrm/amd/display: remove oem i2c adapter on finishEPSS 0.1%CVE-2024-9483MEDIUMUninitialized variable in digital signiture verification may crash the applicationEPSS 0.1%CVE-2026-47335MEDIUMNULL pointer dereference in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2026-13070MEDIUMImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process TerminationEPSS 0.1%CVE-2025-8090MEDIUMVulnerability in the QNX Neutrino Kernel impacts the QNX Software Development Platform and QNX OS for SafetyEPSS 0.1%CVE-2025-60495MEDIUMA segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows atEPSS 0.1%CVE-2025-9337MEDIUMA null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, whiEPSS 0.1%CVE-2026-19411LOWShim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns nullEPSS 0.1%CVE-2026-10659MEDIUMNULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resumeEPSS 0.1%CVE-2026-9759MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2024-32666MEDIUMNULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denialEPSS 0.1%CVE-2025-33237MEDIUMNVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference issue. A successful eEPSS 0.1%