Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-49130MEDIUMath11k: mhi: use mhi_sync_power_up()EPSS 0.3%CVE-2022-49319MEDIUMiommu/arm-smmu-v3: check return value after calling platform_get_resource()EPSS 0.3%CVE-2022-49527MEDIUMmedia: venus: hfi: avoid null dereference in deinitEPSS 0.3%CVE-2025-38049MEDIUMx86/resctrl: Fix allocation of cleanest CLOSID on platforms with no monitorsEPSS 0.3%CVE-2023-52984MEDIUMnet: phy: dp83822: Fix null pointer access on DP83825/DP83826 devicesEPSS 0.3%CVE-2026-76927MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.3%CVE-2022-49282MEDIUMf2fs: quota: fix loop condition at f2fs_quota_sync()EPSS 0.3%CVE-2025-50952MEDIUMopenjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.EPSS 0.3%CVE-2023-3212—A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evicEPSS 0.3%CVE-2024-41866MEDIUMAdobe Indesign 2024 DOC File Parsing Null Pointer DereferenceEPSS 0.3%CVE-2022-49070MEDIUMfbdev: Fix unregistering of framebuffers without deviceEPSS 0.3%CVE-2022-49061MEDIUMnet: ethernet: stmmac: fix altr_tse_pcs function when using a fixed-linkEPSS 0.3%CVE-2022-49523MEDIUMath11k: disable spectral scan during spectral deinitEPSS 0.3%CVE-2022-49453MEDIUMsoc: ti: ti_sci_pm_domains: Check for null return of devm_kcallocEPSS 0.3%CVE-2022-49329MEDIUMvduse: Fix NULL pointer dereference on sysfs accessEPSS 0.3%CVE-2022-49184MEDIUMnet: sparx5: switchdev: fix possible NULL pointer dereferenceEPSS 0.3%CVE-2022-49445MEDIUMpinctrl: renesas: core: Fix possible null-ptr-deref in sh_pfc_map_resources()EPSS 0.3%CVE-2022-49487MEDIUMmtd: rawnand: intel: fix possible null-ptr-deref in ebu_nand_probe()EPSS 0.3%CVE-2022-49448MEDIUMsoc: bcm: Check for NULL return of devm_kzalloc()EPSS 0.3%CVE-2023-22999MEDIUMIn the Linux kernel before 5.16.3, drivers/usb/dwc3/dwc3-qcom.c misinterprets the dwc3_qcom_create_urs_usb_platdev return value (expects it EPSS 0.3%