Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2023-44341MEDIUMAdobe InDesign CC 2023 Memory Corruption Vulnerability IEPSS 0.3%CVE-2023-6679MEDIUMKernel: null pointer dereference in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.cEPSS 0.3%CVE-2025-62791MEDIUMWazuh vulnerable to NULL pointer dereference in DecodeCiscatEPSS 0.3%CVE-2023-47466LOWTagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is tEPSS 0.3%CVE-2025-43966LOWlibheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.EPSS 0.3%CVE-2024-24443MEDIUMAn uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface CN5G AMF (oai-cn5g-aEPSS 0.3%CVE-2022-44368MEDIUMNASM v2.16 was discovered to contain a null pointer deference in the NASM componentEPSS 0.3%CVE-2022-44369MEDIUMNASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.EPSS 0.3%CVE-2025-30272MEDIUMQTS, QuTS heroEPSS 0.3%CVE-2023-51368MEDIUMQTS, QuTS heroEPSS 0.3%CVE-2025-10256MEDIUMFfmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)EPSS 0.3%CVE-2024-50265MEDIUMocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove()EPSS 0.3%CVE-2022-1671—A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attackEPSS 0.3%CVE-2025-30274MEDIUMQTS, QuTS heroEPSS 0.3%CVE-2026-58101HIGHCrypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereferenceEPSS 0.3%CVE-2026-21680MEDIUMiccDEV has Null Pointer Dereference in CIccProfile::CheckTagTypes()EPSS 0.3%CVE-2022-35087MEDIUMSWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.EPSS 0.3%CVE-2023-27114MEDIUMradare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.EPSS 0.3%CVE-2024-25260MEDIUMelfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.EPSS 0.3%CVE-2026-16846MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%