Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-32849MEDIUMNetBSD Signed Integer Overflow in cryptodev_op via cryptodev.cEPSS 0.2%CVE-2026-10670MEDIUMUser-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifierEPSS 0.2%CVE-2024-6157MEDIUMAn attacker who successfully exploited these vulnerabilities could cause the robot to stop. A vulnerability exists in the PROFINET stack EPSS 0.2%CVE-2022-41592LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41595LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41603LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41594LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41593LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41598LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2024-58066MEDIUMclk: mmp: pxa1908-apbcp: Fix a NULL vs IS_ERR() checkEPSS 0.1%CVE-2025-6398MEDIUMA null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a speciaEPSS 0.1%CVE-2024-0086MEDIUMCVEEPSS 0.1%CVE-2025-63745MEDIUMA NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binarEPSS 0.1%CVE-2024-58073MEDIUMdrm/msm/dpu: check dpu_plane_atomic_print_state() for valid ssppEPSS 0.1%CVE-2024-58065MEDIUMclk: mmp: pxa1908-apbc: Fix NULL vs IS_ERR() checkEPSS 0.1%CVE-2023-53384MEDIUMwifi: mwifiex: avoid possible NULL skb pointer dereferenceEPSS 0.1%CVE-2024-58067MEDIUMclk: mmp: pxa1908-mpmu: Fix a NULL vs IS_ERR() checkEPSS 0.1%CVE-2023-53440HIGHnilfs2: fix sysfs interface lifetimeEPSS 0.1%CVE-2023-53289MEDIUMmedia: bdisp: Add missing check for create_workqueueEPSS 0.1%CVE-2025-8735MEDIUMGNU cflow Lexer c.c yylex null pointer dereferenceEPSS 0.1%