Weaknesses of type CWE-476

2,334 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-24194HIGHrobdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-parse.c.EPSS 0.4%CVE-2025-30670MEDIUMZoom Workplace Apps for Windows - Null PointerEPSS 0.4%CVE-2025-30645HIGHJunos OS: SRX Series: Transmission of specific control traffic sent out of a DS-Lite tunnel results in flowd crashEPSS 0.4%CVE-2021-39251MEDIUMA crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.EPSS 0.4%CVE-2025-25473MEDIUMFFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.EPSS 0.4%CVE-2025-64335HIGHSuricata is vulnerable to a null deref when used with base64_dataEPSS 0.4%CVE-2025-9166HIGHRockwell Automation ControlLogix® 5580 V35.013 Denial-Of-ServiceEPSS 0.4%CVE-2026-45729MEDIUMThorVG: Null pointer dereference in SVG loader causes crash via 6-byte malformed inputEPSS 0.4%CVE-2022-25710HIGHDenial of service due to null pointer dereference when GATT is disconnected in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon IndustriEPSS 0.4%CVE-2026-78126MEDIUMstrongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.EPSS 0.4%CVE-2024-35618HIGHPingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.EPSS 0.4%CVE-2025-65565HIGHA denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP asEPSS 0.4%CVE-2025-41414HIGHBIG-IP HTTP/2 vulnerabilityEPSS 0.4%CVE-2022-25741HIGHDenial of service in WLAN due to potential null pointer dereference while accessing the memory location in Snapdragon Auto, Snapdragon CompuEPSS 0.4%CVE-2026-18638MEDIUMVelociraptor server crash via the SetPassword APIEPSS 0.4%CVE-2026-47276MEDIUMNULL Pointer Dereference in REST API properties_parse via Malformed user_propertiesEPSS 0.4%CVE-2026-81490HIGHMongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of SQL ServiceEPSS 0.4%CVE-2023-33461MEDIUMiniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getEPSS 0.4%CVE-2025-62785MEDIUMWazuh fillData NULL pointer dereference causes analysisd crashEPSS 0.4%CVE-2024-28584LOWNull Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) EPSS 0.4%