Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-19888HIGHNULL pointer dereference in SCRAM client-final-message parsing in PgBouncerEPSS 0.4%CVE-2026-25165HIGHPerformance Counters for Windows Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2022-47021HIGHA null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows atEPSS 0.4%CVE-2025-32787LOWSoftEtherVPN Affected by NULL dereference in DeleteIPv6DefaultRouterInRAEPSS 0.4%CVE-2024-43167LOWUnbound: null pointer dereference in unboundEPSS 0.4%CVE-2026-10678HIGHNULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controllerEPSS 0.4%CVE-2025-2957HIGHTRENDnet TEW-411BRP+ HTTP Request httpd sub_401DB0 null pointer dereferenceEPSS 0.4%CVE-2025-2956HIGHTRENDnet TI-G102i HTTP Request lighttpd plugins_call_handle_uri_raw null pointer dereferenceEPSS 0.4%CVE-2026-41069MEDIUMlibheif allows Out-of-bounds vector access leading to invalid dereference (DoS)EPSS 0.4%CVE-2021-47476MEDIUMcomedi: ni_usb6501: fix NULL-deref in command pathsEPSS 0.4%CVE-2021-4095—A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unpriviEPSS 0.4%CVE-2025-23100HIGHAn issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of SeEPSS 0.4%CVE-2025-24251MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS SonoEPSS 0.4%CVE-2021-4145—A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced EPSS 0.4%CVE-2026-33907MEDIUMElla Core Panics during NAS Authentication Response/Failure with missing IEsEPSS 0.4%CVE-2026-45747HIGHSuricata lua/tls: null dereference in TlsGetCertInfoEPSS 0.4%CVE-2024-25073MEDIUMAn issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, ExEPSS 0.4%CVE-2025-57155HIGHNULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a (newer commit after EPSS 0.4%CVE-2026-24641LOWA NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, ForEPSS 0.4%CVE-2025-4476MEDIUMLibsoup: null pointer dereference in libsoup may lead to denial of serviceEPSS 0.4%