Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-53006MEDIUMSubstance3D - Modeler | NULL Pointer Dereference (CWE-476)EPSS 0.4%CVE-2024-12653MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x22040C null pointer dereferenceEPSS 0.4%CVE-2025-62609MEDIUMMLX has Wild Pointer Dereference in load_gguf()EPSS 0.4%CVE-2025-8033MEDIUMIncorrect JavaScript state machine for generatorsEPSS 0.4%CVE-2024-12657MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E000 null pointer dereferenceEPSS 0.4%CVE-2025-65493HIGHNULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLSEPSS 0.4%CVE-2024-39132MEDIUMA NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function VerifyCommaEPSS 0.4%CVE-2026-26456HIGHA null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccdEPSS 0.4%CVE-2024-37820MEDIUMA nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation.EPSS 0.4%CVE-2025-63648HIGHA NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackerEPSS 0.4%CVE-2026-75618HIGHRTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101EPSS 0.4%CVE-2022-2476—A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL =====================EPSS 0.4%CVE-2025-49694HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-3012MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.4%CVE-2019-16230MEDIUMdrivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointeEPSS 0.4%CVE-2026-32738MEDIUMlibheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunkEPSS 0.4%CVE-2025-29838HIGHWindows ExecutionContext Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-42902MEDIUMMemory Corruption vulnerability in SAP Netweaver AS ABAP and ABAP PlatformEPSS 0.4%CVE-2025-30268MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2025-29901HIGHFile Station 5EPSS 0.4%