Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-49615MEDIUMASoC: rt711-sdca: fix kernel NULL pointer dereference when IO errorEPSS 0.3%CVE-2026-3202MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.3%CVE-2025-69649MEDIUMGNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header EPSS 0.3%CVE-2025-8844MEDIUMNASM Netwide Assember preproc.c parse_smacro_template null pointer dereferenceEPSS 0.3%CVE-2023-34323MEDIUMxenstored: A transaction conflict can crash C XenstoredEPSS 0.3%CVE-2024-25453MEDIUMBento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.EPSS 0.3%CVE-2024-26744MEDIUMRDMA/srpt: Support specifying the srpt_service_guid parameterEPSS 0.3%CVE-2024-56634MEDIUMgpio: grgpio: Add NULL check in grgpio_probeEPSS 0.3%CVE-2022-3202—A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attaEPSS 0.3%CVE-2024-50117HIGHdrm/amd: Guard against bad data for ATIF ACPI methodEPSS 0.3%CVE-2024-50296MEDIUMnet: hns3: fix kernel crash when uninstalling driverEPSS 0.3%CVE-2024-56587MEDIUMleds: class: Protect brightness_show() with led_cdev->led_access mutexEPSS 0.3%CVE-2024-45828MEDIUMi3c: mipi-i3c-hci: Mask ring interrupts before ring stop requestEPSS 0.3%CVE-2025-6375MEDIUMpoco MultipartReader.cpp MultipartInputStream null pointer dereferenceEPSS 0.3%CVE-2024-2496MEDIUMLibvirt: null pointer dereference in udevconnectlistallinterfaces()EPSS 0.3%CVE-2023-37026MEDIUMA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95EPSS 0.3%CVE-2024-48881MEDIUMbcache: revert replacing IS_ERR_OR_NULL with IS_ERR againEPSS 0.3%CVE-2021-47645MEDIUMmedia: staging: media: zoran: calculate the right buffer number for zoran_reap_stat_comEPSS 0.3%CVE-2026-47307MEDIUMNULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembEPSS 0.3%CVE-2025-22031MEDIUMPCI/bwctrl: Fix NULL pointer dereference on bus number exhaustionEPSS 0.3%