Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-49184MEDIUMnet: sparx5: switchdev: fix possible NULL pointer dereferenceEPSS 0.3%CVE-2022-49569MEDIUMspi: bcm2835: bcm2835_spi_handle_err(): fix NULL pointer deref for non DMA transfersEPSS 0.3%CVE-2022-49448MEDIUMsoc: bcm: Check for NULL return of devm_kzalloc()EPSS 0.3%CVE-2022-49061MEDIUMnet: ethernet: stmmac: fix altr_tse_pcs function when using a fixed-linkEPSS 0.3%CVE-2022-49487MEDIUMmtd: rawnand: intel: fix possible null-ptr-deref in ebu_nand_probe()EPSS 0.3%CVE-2022-47024HIGHA null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attEPSS 0.3%CVE-2022-49096HIGHnet: sfc: add missing xdp queue reinitializationEPSS 0.3%CVE-2021-47652MEDIUMvideo: fbdev: smscufx: Fix null-ptr-deref in ufx_usb_probe()EPSS 0.3%CVE-2022-49476MEDIUMmt76: mt7921: fix kernel crash at mt7921_pci_removeEPSS 0.3%CVE-2024-56536MEDIUMwifi: cw1200: Fix potential NULL dereferenceEPSS 0.3%CVE-2021-47386HIGHhwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure fieldEPSS 0.3%CVE-2024-53060MEDIUMdrm/amdgpu: prevent NULL pointer dereference if ATIF is not supportedEPSS 0.3%CVE-2023-46051LOWTeX Live 944e257 allows a NULL pointer dereference in texk/web2c/pdftexdir/tounicode.c. NOTE: this is disputed because it should be categoriEPSS 0.3%CVE-2022-49483MEDIUMdrm/msm/disp/dpu1: avoid clearing hw interrupts if hw_intr is null during drm uninitEPSS 0.3%CVE-2024-20312HIGHA vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allEPSS 0.3%CVE-2023-6915MEDIUMKernel: null pointer dereference vulnerability in ida_free in lib/idr.cEPSS 0.3%CVE-2022-49510MEDIUMdrm/omap: fix NULL but dereferenced coccicheck errorEPSS 0.3%CVE-2024-50153MEDIUMscsi: target: core: Fix null-ptr-deref in target_alloc_device()EPSS 0.3%CVE-2022-49615MEDIUMASoC: rt711-sdca: fix kernel NULL pointer dereference when IO errorEPSS 0.3%CVE-2022-49618MEDIUMpinctrl: aspeed: Fix potential NULL dereference in aspeed_pinmux_set_mux()EPSS 0.3%