Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-47466MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47465MEDIUMIn vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.EPSS 0.1%CVE-2022-47468MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47467MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-48443MEDIUMIn telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution EPSS 0.1%CVE-2022-48445MEDIUMIn telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution EPSS 0.1%CVE-2022-48444MEDIUMIn telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution EPSS 0.1%CVE-2025-31711MEDIUMIn cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additEPSS 0.1%CVE-2026-24929MEDIUMOut-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2022-48442MEDIUMIn dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution priEPSS 0.1%CVE-2025-21433MEDIUMNULL Pointer Dereference in SPS-HLOSEPSS 0.1%CVE-2025-59606HIGHNULL Pointer Dereference in HLOSEPSS 0.1%CVE-2025-59604HIGHNULL Pointer Dereference in SPS ApplicationsEPSS 0.1%CVE-2026-100890MEDIUMTrusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode null pointer dereferenceEPSS —CVE-2026-100895MEDIUMTrusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereferenceEPSS —