Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2025-63647HIGHA NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attackers to cause a Denial EPSS 0.4%CVE-2021-42373—A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is givenEPSS 0.4%CVE-2025-20045HIGHBIG-IP SIP MRF VulnerabilityEPSS 0.4%CVE-2024-52833MEDIUMSubstance3D - Modeler | NULL Pointer Dereference (CWE-476)EPSS 0.4%CVE-2024-36832HIGHA NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web requeEPSS 0.4%CVE-2025-54147LOWQsync CentralEPSS 0.4%CVE-2025-48722LOWQsync CentralEPSS 0.4%CVE-2025-52984HIGHJunos OS and Junos OS Evolved: When a static route points to a reject next-hop and a gNMI query for this route is processed, RPD crashesEPSS 0.4%CVE-2025-70116MEDIUMA NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing desEPSS 0.4%CVE-2025-47209LOWQsync CentralEPSS 0.4%CVE-2025-45333HIGHberkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing moduEPSS 0.4%CVE-2025-30266LOWQsync CentralEPSS 0.4%CVE-2022-25733HIGHNull Pointer Dereference in MODEMEPSS 0.4%CVE-2022-25735HIGHNull Pointer Dereference in MODEMEPSS 0.4%CVE-2023-42754MEDIUMKernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()EPSS 0.4%CVE-2026-6666MEDIUMPgBouncer crash in kill_pool_logins_server_errorEPSS 0.4%CVE-2023-37028MEDIUMA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95EPSS 0.4%CVE-2025-50635HIGHA null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function ofEPSS 0.4%CVE-2025-7462MEDIUMArtifex GhostPDL New Output File Open Error gdevpdf.c pdf_ferror null pointer dereferenceEPSS 0.4%CVE-2026-82055HIGHNull Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of ServiceEPSS 0.4%