Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2023-33109HIGHNULL Pointer Dereference in WLAN FirmwareEPSS 0.3%CVE-2025-65566HIGHA denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF EPSS 0.3%CVE-2024-41130MEDIUMllama.cpp null pointer dereference in gguf_init_from_fileEPSS 0.3%CVE-2026-15891HIGHNULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gatewayEPSS 0.3%CVE-2025-52585HIGHBIG-IP Client SSL profile vulnerabilityEPSS 0.3%CVE-2022-29201MEDIUMMissing validation in `QuantizedConv2D` results in undefined behavior in TensorFlowEPSS 0.3%CVE-2025-47111MEDIUMAcrobat Reader | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2026-33903MEDIUMElla Core panics when processing a crafted NGAP LocationReport messageEPSS 0.3%CVE-2022-48509—Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulEPSS 0.3%CVE-2025-53592LOWQTS, QuTS heroEPSS 0.3%CVE-2026-50315HIGHWindows Image Acquisition Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-34683MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a nuEPSS 0.3%CVE-2026-77489HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-44013LOWQTS, QuTS heroEPSS 0.3%CVE-2026-24716LOWQTS, QuTS heroEPSS 0.3%CVE-2025-62850MEDIUMQuTS heroEPSS 0.3%CVE-2025-54326HIGHAn issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in theEPSS 0.3%CVE-2026-45151LOWNanoMQ: NULL Pointer DereferenceEPSS 0.3%CVE-2025-54334HIGHAn issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL PointEPSS 0.3%CVE-2025-54332HIGHAn issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Dereference of profiler.noEPSS 0.3%