Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-24409HIGHiccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlFloatNum<>::ParseXml()EPSS 0.4%CVE-2025-57613HIGHAn issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input() constructor functEPSS 0.4%CVE-2023-25672HIGHTensorFlow has Null Pointer Error in LookupTableImportV2EPSS 0.4%CVE-2025-57612HIGHAn issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name() method allows an attEPSS 0.4%CVE-2025-57615HIGHAn issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new constructor functionEPSS 0.4%CVE-2026-21485HIGHiccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()EPSS 0.4%CVE-2026-21688HIGHiccDEV has Type Confusion in SIccCalcOp::ArgsPushed() at IccProfLib/IccMpeCalc.cppEPSS 0.4%CVE-2022-41843MEDIUMAn issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-3892EPSS 0.4%CVE-2025-64169MEDIUMWazuh NULL pointer dereference in fim_alert line 666EPSS 0.4%CVE-2022-49928HIGHSUNRPC: Fix null-ptr-deref when xps sysfs alloc failedEPSS 0.4%CVE-2025-0221MEDIUMIOBit Protected Folder IOCTL pffilter.sys 0x22200c null pointer dereferenceEPSS 0.4%CVE-2025-0223MEDIUMIObit Protected Folder IOCTL IURegistryFilter.sys 0x8001E010 null pointer dereferenceEPSS 0.4%CVE-2025-0222MEDIUMIObit Protected Folder IOCTL IUProcessFilter.sys 0x8001E004 null pointer dereferenceEPSS 0.4%CVE-2026-0401MEDIUMA post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.EPSS 0.4%CVE-2023-31081MEDIUMAn issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vEPSS 0.4%CVE-2025-60019LOWGlib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via g_tls_bio_new_from_iostream() and g_tls_bio_new_from_datagram_based()EPSS 0.4%CVE-2023-2871LOWFabulaTech USB for Remote Desktop IoControlCode 0x220408 null pointer dereferenceEPSS 0.4%CVE-2026-20727HIGHNull pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. UnEPSS 0.4%CVE-2026-17273MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.4%CVE-2025-20262MEDIUMCisco Nexus 3000 and 9000 Series Switches Protocol Independent Multicast Version 6 Denial of Service VulnerabilityEPSS 0.4%