Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-41597LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-50388MEDIUMnvme: fix multipath crash caused by flush request when blktrace is enabledEPSS 0.2%CVE-2025-39807MEDIUMdrm/mediatek: Add error handling for old state CRTC in atomic_disableEPSS 0.2%CVE-2026-90995MEDIUMSssd: sssd: local denial of service due to null pointer dereference in pam responderEPSS 0.2%CVE-2023-53273MEDIUMDrivers: vmbus: Check for channel allocation before looking up relidsEPSS 0.2%CVE-2025-39811MEDIUMdrm/xe/vm: Clear the scratch_pt pointer on errorEPSS 0.2%CVE-2023-53210MEDIUMmd/raid5-cache: fix null-ptr-deref for r5l_flush_stripe_to_raid()EPSS 0.2%CVE-2022-50383MEDIUMmedia: mediatek: vcodec: Can't set dst buffer to done when lat decode errorEPSS 0.2%CVE-2026-22722MEDIUMVMware Workstation for Windows null pointer dereference may allow an authenticated user to trigger a crashEPSS 0.2%CVE-2025-47119MEDIUMAdobe Framemaker | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2023-53209MEDIUMwifi: mac80211_hwsim: Fix possible NULL dereferenceEPSS 0.2%CVE-2026-45204MEDIUMGPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memoryEPSS 0.2%CVE-2026-24263HIGHNVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer derefereEPSS 0.2%CVE-2023-53240MEDIUMxsk: check IFF_UP earlier in Tx pathEPSS 0.2%CVE-2024-48294MEDIUMA NULL pointer dereference in the component libPdfCore.dll of Wondershare PDF Reader v1.0.9.2544 allows attackers to cause a Denial of ServiEPSS 0.2%CVE-2026-93689MEDIUMWinFsp through 2.2.26215 NULL Pointer Dereference via Fast I/OEPSS 0.2%CVE-2025-55312HIGHAn issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScriEPSS 0.2%CVE-2026-10648MEDIUMNULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustionEPSS 0.2%CVE-2025-24483MEDIUMNULL pointer dereference vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially cEPSS 0.2%CVE-2026-47753MEDIUMIncus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)EPSS 0.2%