Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2025-59668HIGHMultiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafted certain UDP packetEPSS 0.5%CVE-2023-46867MEDIUMIn International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a NULL pointer derefeEPSS 0.5%CVE-2017-12153—A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This fEPSS 0.5%CVE-2026-10852MEDIUMWebsphere Application Server is Affected By a Denial of ServiceEPSS 0.5%CVE-2025-45835HIGHA null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function ofEPSS 0.5%CVE-2026-9752HIGHGeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generationEPSS 0.5%CVE-2026-9743HIGHAggregation sub-pipeline null dereference may allow DoS via crafted getMoreEPSS 0.5%CVE-2025-48728MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-47213MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-48729MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-27917HIGHAn issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOSEPSS 0.5%CVE-2023-33089HIGHNULL Pointer Dereference in WLAN FirmwareEPSS 0.5%CVE-2026-41684MEDIUMIncus: Nil Dereferences on Restore via Malformed YAMLEPSS 0.5%CVE-2026-41647MEDIUMIncus: Nil-Pointer Dereference via S3 Bucket ImportEPSS 0.5%CVE-2025-66720HIGHNull pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId.EPSS 0.5%CVE-2025-48726MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-48727MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-52427MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-47214MEDIUMQTSEPSS 0.5%CVE-2023-2609HIGHNULL Pointer Dereference in vim/vimEPSS 0.5%