Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2023-4681MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.3%CVE-2024-55511HIGHA null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system crash or potentiallyEPSS 0.3%CVE-2024-45238HIGHAn issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync oEPSS 0.3%CVE-2022-1852—A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn inEPSS 0.3%CVE-2024-45235HIGHAn issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync oEPSS 0.3%CVE-2025-64086MEDIUMA NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to causEPSS 0.3%CVE-2025-64085MEDIUMA NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows attackers to cause a DeEPSS 0.3%CVE-2025-65408MEDIUMA NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allEPSS 0.3%CVE-2023-47076MEDIUMAdobe InDesign CC 2023 Memory Corruption Vulnerability IV.EPSS 0.3%CVE-2020-27830—A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checkEPSS 0.3%CVE-2023-43898MEDIUMNothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attaEPSS 0.3%CVE-2026-10593MEDIUMRemotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handlingEPSS 0.3%CVE-2025-24179MEDIUMA null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macEPSS 0.3%CVE-2023-6397MEDIUM A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX serieEPSS 0.3%CVE-2021-0111MEDIUMNULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of priEPSS 0.3%CVE-2025-22063MEDIUMnetlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 socketsEPSS 0.3%CVE-2024-0841MEDIUMKernel: hugetlbfs: null pointer dereference in hugetlbfs_fill_super functionEPSS 0.3%CVE-2022-49568MEDIUMKVM: Don't null dereference ops->destroyEPSS 0.3%CVE-2025-39851HIGHvxlan: Fix NPD when refreshing an FDB entry with a nexthop objectEPSS 0.3%CVE-2026-24826CRITICALOut-of-bounds write in turso3dEPSS 0.3%