Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2025-30268MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2025-30267MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2025-22921MEDIUMFFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.EPSS 0.4%CVE-2025-49686HIGHWindows TCP/IP Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-1186LOWFabulaTech Webcam for Remote Desktop IOCTL ftwebcam.sys 0x222018 null pointer dereferenceEPSS 0.4%CVE-2025-45332HIGHvkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leadinEPSS 0.4%CVE-2022-1201HIGHNULL Pointer Dereference in mrb_vm_exec with super in mruby/mrubyEPSS 0.4%CVE-2024-56430LOWOpenFHE through 1.2.3 has a NULL pointer dereference in BinFHEContext::EvalFloor in lib/binfhe-base-scheme.cpp.EPSS 0.4%CVE-2024-27229HIGHIn ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lEPSS 0.4%CVE-2024-44101HIGHthere is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service witEPSS 0.4%CVE-2026-79590MEDIUMA NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted RuEPSS 0.4%CVE-2020-25639—A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way thEPSS 0.4%CVE-2025-20755MEDIUMIn Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has cEPSS 0.4%CVE-2024-30295HIGHWhen Animate parses FLA files, there is a UAF vulnerability caused by referencing uninitialized memory at Animate.exe+0x1149dcfEPSS 0.4%CVE-2026-24411HIGHiccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlSegmentedCurve::ToXml()EPSS 0.4%CVE-2025-20647MEDIUMIn Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connectedEPSS 0.4%CVE-2026-55717MEDIUM'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crashEPSS 0.4%CVE-2025-50950HIGHAudiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.EPSS 0.4%CVE-2026-24409HIGHiccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlFloatNum<>::ParseXml()EPSS 0.4%CVE-2026-24410HIGHiccDEV has Undefined Behavior and Null Pointer Deference in CIccProfileXml::ParseBasic()EPSS 0.4%