Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2025-7007HIGHNull pointer dereference in Avast Antivirus on macOS (16.0.0) or Linux (3.0.3)EPSS 0.1%CVE-2025-46592MEDIUMNull pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availabEPSS 0.1%CVE-2025-60477MEDIUMA NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before EPSS 0.1%CVE-2025-13425LOWDenial of Service in OSV-SCALIBREPSS 0.1%CVE-2024-56188MEDIUMthere is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with no additional execuEPSS 0.1%CVE-2023-33036HIGHNULL Pointer Dereference in HypervisorEPSS 0.1%CVE-2024-47290MEDIUMInput validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2021-25491LOWA vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.EPSS 0.1%CVE-2026-20771MEDIUMNull pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow aEPSS 0.1%CVE-2025-27701MEDIUMIn the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_arraEPSS 0.1%CVE-2026-20914MEDIUMNull pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow EPSS 0.1%CVE-2026-20064MEDIUMA vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device tEPSS 0.1%CVE-2024-23357MEDIUMNULL Pointer Dereference in HLOSEPSS 0.1%CVE-2025-53170MEDIUMNull pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vulnerability may affectEPSS 0.1%CVE-2022-48231MEDIUMIn soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privEPSS 0.1%CVE-2022-48241MEDIUMIn telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution EPSS 0.1%CVE-2022-44447MEDIUMIn wlan driver, there is a possible null pointer dereference issue due to a missing bounds check. This could lead to local denial of serviceEPSS 0.1%CVE-2024-27232MEDIUMIn asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclEPSS 0.1%CVE-2026-17009MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2024-29751MEDIUMIn asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information EPSS 0.1%