Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-53952MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2022-49731MEDIUMata: libata-core: fix NULL pointer deref in ata_host_alloc_pinfo()EPSS 0.3%CVE-2024-49531MEDIUMAcrobat Reader | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2023-53399HIGHksmbd: fix NULL pointer dereference in smb2_get_info_filesystem()EPSS 0.3%CVE-2022-49707MEDIUMext4: add reserved GDT blocks checkEPSS 0.3%CVE-2024-26903MEDIUMBluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_securityEPSS 0.3%CVE-2023-45913MEDIUMMesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability iEPSS 0.3%CVE-2025-65835MEDIUMThe Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiveEPSS 0.3%CVE-2024-26475MEDIUMAn issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grubEPSS 0.3%CVE-2021-47657MEDIUMdrm/virtio: Ensure that objs is not NULL in virtio_gpu_array_put_free()EPSS 0.3%CVE-2022-49335MEDIUMdrm/amdgpu/cs: make commands with 0 chunks illegal behaviour.EPSS 0.3%CVE-2022-49323MEDIUMiommu/arm-smmu: fix possible null-ptr-deref in arm_smmu_device_probe()EPSS 0.3%CVE-2024-30403HIGHJunos OS Evolved: When MAC learning happens, and an interface gets flapped, the PFE crashesEPSS 0.3%CVE-2023-29569MEDIUMCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via ffi_cb_impl_wpwwwww at src/mjs_ffi.c. This vulnerability can lead to EPSS 0.3%CVE-2023-5972HIGHKernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.cEPSS 0.3%CVE-2022-49495MEDIUMdrm/msm/hdmi: check return value after calling platform_get_resource_byname()EPSS 0.3%CVE-2022-49491MEDIUMdrm/rockchip: vop: fix possible null-ptr-deref in vop_bind()EPSS 0.3%CVE-2023-52490MEDIUMmm: migrate: fix getting incorrect page mapping during page migrationEPSS 0.3%CVE-2025-68141HIGHEVerest vulnerable to null pointer dereference during DC_ChargeLoopRes document deserializationEPSS 0.3%CVE-2022-4981MEDIUMDCMTK dcmqrscp dcmqrcnf.cc readPeerList null pointer dereferenceEPSS 0.3%