Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-49608MEDIUMpinctrl: ralink: Check for null return of devm_kcallocEPSS 0.3%CVE-2023-48364HIGHA vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMEPSS 0.3%CVE-2023-48363HIGHA vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMEPSS 0.3%CVE-2023-23000MEDIUMIn the Linux kernel before 5.17, drivers/phy/tegra/xusb.c mishandles the tegra_xusb_find_port_node return value. Callers expect NULL in the EPSS 0.3%CVE-2025-57611MEDIUMAn issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the dump() method allows an attEPSS 0.3%CVE-2022-49232MEDIUMdrm/amd/display: Fix a NULL pointer dereference in amdgpu_dm_connector_add_common_modes()EPSS 0.3%CVE-2025-15504MEDIUMlief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereferenceEPSS 0.3%CVE-2022-49498MEDIUMALSA: pcm: Check for null pointer of pointer substream before dereferencing itEPSS 0.3%CVE-2022-49459MEDIUMthermal/drivers/broadcom: Fix potential NULL dereference in sr_thermal_probeEPSS 0.3%CVE-2022-0168—A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet FileEPSS 0.3%CVE-2022-49375MEDIUMrtc: mt6397: check return value after calling platform_get_resource()EPSS 0.3%CVE-2022-49302MEDIUMUSB: host: isp116x: check return value after calling platform_get_resource()EPSS 0.3%CVE-2026-76650MEDIUMPre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query Processing in TP-Link TL-WR841NEPSS 0.3%CVE-2022-49485MEDIUMdrm/v3d: Fix null pointer dereference of pointer perfmonEPSS 0.3%CVE-2022-49376MEDIUMscsi: sd: Fix potential NULL pointer dereferenceEPSS 0.3%CVE-2022-49449MEDIUMpinctrl: renesas: rzn1: Fix possible null-ptr-deref in sh_pfc_map_resources()EPSS 0.3%CVE-2022-49494MEDIUMmtd: rawnand: cadence: fix possible null-ptr-deref in cadence_nand_dt_probe()EPSS 0.3%CVE-2022-49221MEDIUMdrm/msm/dp: populate connector of struct dp_panelEPSS 0.3%CVE-2022-49187MEDIUMclk: Fix clk_hw_get_clk() when dev is NULLEPSS 0.3%CVE-2023-23005MEDIUMIn the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case,EPSS 0.3%