Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-22210MEDIUMJunos OS: QFX5000 Series and MX Series: An l2alm crash leading to an FPC crash can be observed in VxLAN scenarioEPSS 0.3%CVE-2023-6622MEDIUMKernel: null pointer dereference vulnerability in nft_dynset_init()EPSS 0.3%CVE-2019-10140MEDIUMA vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a deEPSS 0.3%CVE-2022-29205MEDIUMSegfault due to missing support for quantized types in TensorFlowEPSS 0.3%CVE-2026-21689MEDIUMiccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cppEPSS 0.3%CVE-2024-12662MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E040 null pointer dereferenceEPSS 0.3%CVE-2023-4683MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.3%CVE-2023-1628MEDIUMJianming Antivirus IoControlCode kvcore.sys null pointer dereferenceEPSS 0.3%CVE-2020-35505—A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurEPSS 0.3%CVE-2023-45925—GNU Midnight Commander 4.8.29-146-g299d9a2fb was discovered to contain a NULL pointer dereference via the function x_error_handler() at tty/EPSS 0.3%CVE-2025-1373MEDIUMFFmpeg MOV Parser mov.c mov_read_trak null pointer dereferenceEPSS 0.3%CVE-2026-78130HIGHstrongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.EPSS 0.3%CVE-2025-13406MEDIUMScanning for higher HART revision device leads into NULL pointer dereference in live listEPSS 0.3%CVE-2026-53463MEDIUMImageMagick: Null Pointer Dereference in distort operation when passing incorrect argumentsEPSS 0.3%CVE-2026-93588LOWImageMagick before 7.1.2-31 Null Pointer Dereference via PNMEPSS 0.3%CVE-2026-33970LOWAn issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330EPSS 0.3%CVE-2024-12656MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x220448 null pointer dereferenceEPSS 0.3%CVE-2025-59351LOWDragonfly possibly panics due to nil pointer dereference when using variables created alongside an errorEPSS 0.3%CVE-2023-44341MEDIUMAdobe InDesign CC 2023 Memory Corruption Vulnerability IEPSS 0.3%CVE-2026-12329MEDIUMMemory safety bug fixed in Thunderbird ESR 140.12EPSS 0.3%