Weaknesses of type CWE-476

2,335 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-20794MEDIUMAdobe Animate 2024 WAV File Parsing Null Pointer DereferenceEPSS 0.3%CVE-2023-37035MEDIUMA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95EPSS 0.3%CVE-2026-47307MEDIUMNULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembEPSS 0.3%CVE-2023-37026MEDIUMA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95EPSS 0.3%CVE-2023-52858MEDIUMclk: mediatek: clk-mt7629: Add check for mtk_alloc_clk_dataEPSS 0.3%CVE-2023-40032MEDIUMPotential segfault due to NULL pointer dereference in libvipsEPSS 0.3%CVE-2023-52844MEDIUMmedia: vidtv: psi: Add check for kstrdupEPSS 0.3%CVE-2026-44710MEDIUMpam_usb: NULL pointer dereference from UDisks device fields causes PAM crash and login denial-of-serviceEPSS 0.3%CVE-2023-52765MEDIUMmfd: qcom-spmi-pmic: Fix revid implementationEPSS 0.3%CVE-2022-49295HIGHnbd: call genl_unregister_family() first in nbd_cleanup()EPSS 0.3%CVE-2025-2926MEDIUMHDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereferenceEPSS 0.3%CVE-2024-38548MEDIUMdrm: bridge: cdns-mhdp8546: Fix possible null pointer dereferenceEPSS 0.3%CVE-2025-21642MEDIUMmptcp: sysctl: sched: avoid using current->nsproxyEPSS 0.3%CVE-2024-24445MEDIUMOpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protocol messages which alEPSS 0.3%CVE-2026-16829MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2024-43759MEDIUMIllustrator | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2023-23001MEDIUMIn the Linux kernel before 5.16.3, drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to be NULL in thEPSS 0.2%CVE-2025-21848MEDIUMnfp: bpf: Add check for nfp_app_ctrl_msg_alloc()EPSS 0.2%CVE-2023-23006MEDIUMIn the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_get_uars_page returnEPSS 0.2%CVE-2023-4459MEDIUMKernel: vmxnet3: null pointer dereference in vmxnet3_rq_cleanup()EPSS 0.2%