Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-32776MEDIUMlibexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.EPSS 0.2%CVE-2023-33088HIGHNULL pointer dereference in WLAN FirmwareEPSS 0.2%CVE-2022-49930MEDIUMRDMA/hns: Fix NULL pointer problem in free_mr_init()EPSS 0.2%CVE-2026-55783LOWNanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom archive handlers when extracting/testing the whole archiveEPSS 0.2%CVE-2026-57225LOWSuricata datasets: NULL pointer dereference in JSON/NDJSON dataset loadingEPSS 0.2%CVE-2026-32778LOWlibexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.EPSS 0.2%CVE-2023-53228MEDIUMdrm/amdgpu: drop redundant sched job cleanup when cs is abortedEPSS 0.2%CVE-2025-23346LOWNVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereference. A successful exEPSS 0.2%CVE-2026-47271MEDIUMpam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentication process crashEPSS 0.2%CVE-2022-49733HIGHALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNCEPSS 0.2%CVE-2022-50402MEDIUMdrivers/md/md-bitmap: check the return value of md_bitmap_get_counter()EPSS 0.2%CVE-2023-53277MEDIUMwifi: iwl3945: Add missing check for create_singlethread_workqueueEPSS 0.2%CVE-2022-50380MEDIUMmm: /proc/pid/smaps_rollup: fix no vma's null-derefEPSS 0.2%CVE-2023-53304MEDIUMnetfilter: nft_set_rbtree: fix overlap expiration walkEPSS 0.2%CVE-2023-53239MEDIUMdrm/msm/mdp5: Add check for kzallocEPSS 0.2%CVE-2023-53280MEDIUMscsi: qla2xxx: Remove unused nvme_ls_waitq wait queueEPSS 0.2%CVE-2023-53223MEDIUMdrm/msm/dsi: Add missing check for alloc_ordered_workqueueEPSS 0.2%CVE-2023-53220MEDIUMmedia: az6007: Fix null-ptr-deref in az6007_i2c_xfer()EPSS 0.2%CVE-2023-53275MEDIUMALSA: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync()EPSS 0.2%CVE-2022-50388MEDIUMnvme: fix multipath crash caused by flush request when blktrace is enabledEPSS 0.2%