Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-43590MEDIUMA null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback technologies CBFS Filter EPSS 0.3%CVE-2022-43589MEDIUMA null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Filter 20.0.8317. A spEPSS 0.3%CVE-2024-49554MEDIUMMedia Encoder | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2022-37290MEDIUMGNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.EPSS 0.3%CVE-2022-43588MEDIUMA null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Filter 20.0.8317. A spEPSS 0.3%CVE-2024-6063MEDIUMGPAC MP4Box dmx_m2ts.c m2tsdmx_on_event null pointer dereferenceEPSS 0.3%CVE-2023-5586MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.3%CVE-2026-19012MEDIUMAuthenticated denial of service in Consul Enterprise-to-Community Edition downgrade pathEPSS 0.3%CVE-2024-53224HIGHRDMA/mlx5: Move events notifier registration to be after device registrationEPSS 0.3%CVE-2023-2872MEDIUMFlexiHub IoControlCode fusbhub.sys 0x220088 null pointer dereferenceEPSS 0.3%CVE-2023-2875MEDIUMeScan Antivirus IoControlCode PROCOBSRVESX.SYS 0x22E008u null pointer dereferenceEPSS 0.3%CVE-2025-40833HIGHThe affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. This could allow an EPSS 0.3%CVE-2022-47094HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pidEPSS 0.3%CVE-2023-43522HIGHNULL Pointer Dereference in WLAN FirmwareEPSS 0.3%CVE-2023-24847HIGHNULL pointer Dereference in ModemEPSS 0.3%CVE-2022-49532MEDIUMdrm/virtio: fix NULL pointer dereference in virtio_gpu_conn_get_modesEPSS 0.3%CVE-2022-1789—With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlEPSS 0.3%CVE-2025-15156MEDIUMomec-project UPF PFCP Session Establishment Request messages_session.go handleSessionEstablishmentRequest null pointer dereferenceEPSS 0.3%CVE-2023-6622MEDIUMKernel: null pointer dereference vulnerability in nft_dynset_init()EPSS 0.3%CVE-2022-22210MEDIUMJunos OS: QFX5000 Series and MX Series: An l2alm crash leading to an FPC crash can be observed in VxLAN scenarioEPSS 0.3%