Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-8359HIGHGladinet Triofox WOSHttpStatusModule.dll NULL Function Pointer Call DoSEPSS 0.5%CVE-2026-30072HIGHA NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crEPSS 0.5%CVE-2026-30069HIGHA NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) EPSS 0.5%CVE-2025-30262MEDIUMQsync CentralEPSS 0.5%CVE-2026-30056HIGHA NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via suEPSS 0.5%CVE-2025-29888MEDIUMFile Station 5EPSS 0.5%CVE-2026-9716HIGHCWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuEPSS 0.5%CVE-2025-29886MEDIUMFile Station 5EPSS 0.5%CVE-2026-92626HIGHControl iD iDSecure Unauthenticated Denial of ServiceEPSS 0.5%CVE-2025-14953LOWOpen5GS FAR-ID handler.c ogs_pfcp_handle_create_pdr null pointer dereferenceEPSS 0.5%CVE-2025-29874MEDIUMFile Station 5EPSS 0.5%CVE-2025-30263MEDIUMQsync CentralEPSS 0.5%CVE-2025-29882MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2026-38344HIGHA NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to causEPSS 0.5%CVE-2026-8850HIGHIBM HTTP Server is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-57434LOWNokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classesEPSS 0.5%CVE-2026-33262MEDIUMInsufficient validation of cookie replyEPSS 0.5%CVE-2023-50432MEDIUMsimple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service (daemon crash) by sending a DHCP packet without any EPSS 0.5%CVE-2024-39130HIGHA NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function DumpOneStream(EPSS 0.5%CVE-2025-66281MEDIUMQTS, QuTS heroEPSS 0.5%