Weaknesses of type CWE-476

2,336 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2023-23006MEDIUMIn the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_get_uars_page returnEPSS 0.2%CVE-2023-23001MEDIUMIn the Linux kernel before 5.16.3, drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to be NULL in thEPSS 0.2%CVE-2024-42329LOWJS - Crash on unexpected HTTP server responseEPSS 0.2%CVE-2025-9384MEDIUMappneta tcpreplay parse_args.c tcpedit_post_args null pointer dereferenceEPSS 0.2%CVE-2021-47503MEDIUMscsi: pm80xx: Do not call scsi_remove_host() in pm8001_alloc()EPSS 0.2%CVE-2024-25454MEDIUMBento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.EPSS 0.2%CVE-2023-52861MEDIUMdrm: bridge: it66121: Fix invalid connector dereferenceEPSS 0.2%CVE-2024-22653MEDIUMyasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c.EPSS 0.2%CVE-2025-10999MEDIUMOpen Babel cacaoformat.cpp SetHilderbrandt null pointer dereferenceEPSS 0.2%CVE-2026-8479MEDIUMIEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messEPSS 0.2%CVE-2022-1249—A NULL pointer dereference flaw was found in pesign's cms_set_pw_data() function of the cms_common.c file. The function fails to handle the EPSS 0.2%CVE-2021-47651MEDIUMsoc: qcom: rpmpd: Check for null return of devm_kcallocEPSS 0.2%CVE-2024-53188HIGHwifi: ath12k: fix crash when unbindingEPSS 0.2%CVE-2023-23002MEDIUMIn the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to bEPSS 0.2%CVE-2025-46399MEDIUMXfig: transfig: fig2dev segmentation fault vulnerabilityEPSS 0.2%CVE-2025-46400MEDIUMXfig: fig2dev segmentation fault in read_arcobjectEPSS 0.2%CVE-2025-30319MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2025-30320MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2025-30321MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2024-53043MEDIUMmctp i2c: handle NULL header addressEPSS 0.2%