Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2025-62817HIGHAn issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of sessiEPSS 0.3%CVE-2022-41841MEDIUMAn issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp, which iEPSS 0.3%CVE-2025-65502MEDIUMNull pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initiEPSS 0.3%CVE-2025-65296MEDIUMNULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in the JSON processing EPSS 0.3%CVE-2022-49472MEDIUMnet: phy: micrel: Allow probing without .driver_dataEPSS 0.3%CVE-2023-23004MEDIUMIn the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in tEPSS 0.3%CVE-2026-21691MEDIUMiccDEV has Type Confusion in CIccTag:IsTypeCompressed()EPSS 0.3%CVE-2023-7042MEDIUMKernel: null pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev()EPSS 0.3%CVE-2020-35538—A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.EPSS 0.3%CVE-2025-20793MEDIUMIn Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connectEPSS 0.3%CVE-2022-49475MEDIUMspi: spi-fsl-qspi: check return value after calling platform_get_resource_byname()EPSS 0.3%CVE-2025-21155MEDIUMSubstance3D - Stager | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2026-10656MEDIUMNULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlersEPSS 0.3%CVE-2026-7376MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.3%CVE-2023-52976MEDIUMefi: fix potential NULL deref in efi_mem_reserve_persistentEPSS 0.3%CVE-2022-28189MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a NUEPSS 0.3%CVE-2022-49400MEDIUMmd: Don't set mddev private to NULL in raid0 pers->freeEPSS 0.3%CVE-2025-68699MEDIUMNanoMQ $share/ Subscription Validation and Forwarding Parsing Inconsistency: NULL Pointer Increment Causes CrashEPSS 0.3%CVE-2024-49531MEDIUMAcrobat Reader | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2024-53952MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.3%