Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2025-62466HIGHWindows Client-Side Caching Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-4751MEDIUMNULL Pointer Dereference in tmate-io tmateEPSS 0.4%CVE-2026-82055HIGHNull Pointer Dereference in MongoDB Server 2dsphere Index Key Generation Leads to Denial of ServiceEPSS 0.4%CVE-2026-18699MEDIUMImproper Input Validation in MongoDB Query Planner Leads to Denial of ServiceEPSS 0.4%CVE-2024-57719MEDIUMlunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.EPSS 0.4%CVE-2025-20790MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connecEPSS 0.4%CVE-2026-34339MEDIUMWindows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityEPSS 0.4%CVE-2026-32216MEDIUMWindows Redirected Drive Buffering System Denial of Service VulnerabilityEPSS 0.4%CVE-2025-30671MEDIUMZoom Workplace Apps for Windows - Null PointerEPSS 0.4%CVE-2021-4158—A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crEPSS 0.4%CVE-2026-86097HIGHPX4 Autopilot through 1.17.0 Null Pointer Dereference via param selectEPSS 0.4%CVE-2023-25663HIGHTensorFlow has Null Pointer Error in TensorArrayConcatV2EPSS 0.4%CVE-2023-25670HIGHTensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantizeEPSS 0.4%CVE-2023-25676HIGHTensorFlow has null dereference on ParallelConcat with XLAEPSS 0.4%CVE-2023-25674HIGHTensorFlow has Null Pointer Error in RandomShuffle with XLA enableEPSS 0.4%CVE-2023-25660HIGHTensorFlow vulnerable to seg fault in `tf.raw_ops.Print`EPSS 0.4%CVE-2023-24910HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2018-14646MEDIUMThe Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the EPSS 0.4%CVE-2025-32398HIGHA NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the libraryEPSS 0.4%CVE-2026-8063HIGHPost-auth null pointer dereference when aggregating against a view with empty search pipelineEPSS 0.4%