Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-49485MEDIUMdrm/v3d: Fix null pointer dereference of pointer perfmonEPSS 0.3%CVE-2022-49187MEDIUMclk: Fix clk_hw_get_clk() when dev is NULLEPSS 0.3%CVE-2025-25471MEDIUMFFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.EPSS 0.3%CVE-2022-49649MEDIUMxen/netback: avoid entering xenvif_rx_next_skb() with an empty rx queueEPSS 0.3%CVE-2025-71004MEDIUMA segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.3%CVE-2022-49139MEDIUMBluetooth: fix null ptr deref on hci_sync_conn_complete_evtEPSS 0.3%CVE-2025-65498MEDIUMNULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a deniaEPSS 0.3%CVE-2025-2588MEDIUMHercules Augeas fa.c re_case_expand null pointer dereferenceEPSS 0.3%CVE-2025-22065MEDIUMidpf: fix adapter NULL pointer dereference on rebootEPSS 0.3%CVE-2025-65501MEDIUMNull pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS EPSS 0.3%CVE-2022-49703MEDIUMscsi: ibmvfc: Store vhost pointer during subcrq allocationEPSS 0.3%CVE-2025-65497MEDIUMNULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a deniaEPSS 0.3%CVE-2023-22997MEDIUMIn the Linux kernel before 6.1.2, kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to be NULL in tEPSS 0.3%CVE-2025-40576MEDIUMA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly valEPSS 0.3%CVE-2025-65496MEDIUMNULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a deniaEPSS 0.3%CVE-2025-65500MEDIUMNULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a deniaEPSS 0.3%CVE-2025-36894HIGHIn TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional executionEPSS 0.3%CVE-2023-53005MEDIUMtrace_events_hist: add check for return value of 'create_hist_field'EPSS 0.3%CVE-2022-49319MEDIUMiommu/arm-smmu-v3: check return value after calling platform_get_resource()EPSS 0.3%CVE-2022-49544MEDIUMipw2x00: Fix potential NULL dereference in libipw_xmit()EPSS 0.3%