Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-6062MEDIUMGPAC MP4Box load_text.c swf_svg_add_iso_sample null pointer dereferenceEPSS 0.3%CVE-2026-7259LOWNull pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()EPSS 0.3%CVE-2025-55659MEDIUMA NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial EPSS 0.3%CVE-2026-16702MEDIUMIBM® Db2® federated server could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereferenceEPSS 0.3%CVE-2026-88373HIGHlibde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zeEPSS 0.3%CVE-2023-20233MEDIUMA vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker EPSS 0.3%CVE-2025-1632MEDIUMlibarchive bsdunzip.c list null pointer dereferenceEPSS 0.3%CVE-2024-37602MEDIUMAn issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible NULL pointer dereference in the Apple CaEPSS 0.3%CVE-2021-33630MEDIUMNULL-ptr-deref in network schedEPSS 0.3%CVE-2022-29206MEDIUMMissing validation results in undefined behavior in `SparseTensorDenseAdd` in TensorFlowEPSS 0.3%CVE-2024-29489MEDIUMJerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.EPSS 0.3%CVE-2025-52865LOWFile Station 5EPSS 0.3%CVE-2025-47207MEDIUMFile Station 5EPSS 0.3%CVE-2025-53408LOWFile Station 5EPSS 0.3%CVE-2020-9085MEDIUMThere is a NULL pointer dereference vulnerability in some Huawei products. An attacker may send specially crafted POST messages to the affecEPSS 0.3%CVE-2023-21593MEDIUMAdobe InDesign SVG file NULL Pointer Dereference Application denial-of-serviceEPSS 0.3%CVE-2024-10037MEDIUMA vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crEPSS 0.3%CVE-2024-41130MEDIUMllama.cpp null pointer dereference in gguf_init_from_fileEPSS 0.3%CVE-2026-28522HIGHarduino-TuyaOpen WiFiUDP Null Pointer Dereference Denial of ServiceEPSS 0.3%CVE-2020-35504—A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guesEPSS 0.3%