Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2025-55780HIGHA null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. SEPSS 0.4%CVE-2024-9472HIGHPAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted TrafficEPSS 0.4%CVE-2023-2731MEDIUMA NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attackerEPSS 0.4%CVE-2025-65564HIGHA denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives aEPSS 0.4%CVE-2025-47205MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2023-1264MEDIUMNULL Pointer Dereference in vim/vimEPSS 0.4%CVE-2022-38928HIGHXPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.EPSS 0.4%CVE-2026-42767MEDIUMNULL Pointer Dereference in CRMF EncryptedValue DecryptionEPSS 0.4%CVE-2025-14309HIGHNULL Pointer Dereference vulnerability in ravynsoft ravynos.This issue affects ravynos: through 0.5.2.EPSS 0.4%CVE-2024-24442HIGHA NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackersEPSS 0.4%CVE-2025-22490MEDIUMFile Station 5EPSS 0.4%CVE-2025-29876MEDIUMFile Station 5EPSS 0.4%CVE-2025-29873MEDIUMFile Station 5EPSS 0.4%CVE-2025-29877MEDIUMFile Station 5EPSS 0.4%CVE-2026-40401HIGHWindows TCP/IP Denial of Service VulnerabilityEPSS 0.4%CVE-2023-2908MEDIUMLibtiff: null pointer dereference in tif_dir.cEPSS 0.4%CVE-2026-34761MEDIUMElla Core Panics Upon NGAP handover failureEPSS 0.4%CVE-2025-41433HIGHBIG-IP SIP ALG profile vulnerabilityEPSS 0.4%CVE-2026-26983MEDIUMImageMagick: Invalid MSL <map> can result in a use after freeEPSS 0.4%CVE-2026-8723MEDIUMqs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnlyEPSS 0.4%