Weaknesses of type CWE-476

2,336 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-4128MEDIUMA NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect timEPSS 0.2%CVE-2023-52855MEDIUMusb: dwc2: fix possible NULL pointer dereference caused by driver concurrencyEPSS 0.2%CVE-2024-53238MEDIUMBluetooth: btmtk: adjust the position to init iso data anchorEPSS 0.2%CVE-2021-46933HIGHusb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear.EPSS 0.2%CVE-2025-57248HIGHA null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file is EPSS 0.2%CVE-2021-47631MEDIUMARM: davinci: da850-evm: Avoid NULL pointer dereferenceEPSS 0.2%CVE-2024-11499MEDIUMA vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to pEPSS 0.2%CVE-2022-34679MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unhandled return value can lead to aEPSS 0.2%CVE-2025-20750MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connecEPSS 0.2%CVE-2022-49104MEDIUMstaging: vchiq_core: handle NULL result of find_service_by_handleEPSS 0.2%CVE-2025-55643MEDIUMA NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a DenialEPSS 0.2%CVE-2022-49931HIGHIB/hfi1: Correctly move list in sc_disable()EPSS 0.2%CVE-2025-55641MEDIUMA NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a EPSS 0.2%CVE-2022-49106MEDIUMstaging: vchiq_arm: Avoid NULL ptr deref in vchiq_dump_platform_instancesEPSS 0.2%CVE-2025-55663MEDIUMA segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attackers to cause a DenialEPSS 0.2%CVE-2025-55649MEDIUMA NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a DeniaEPSS 0.2%CVE-2022-34678MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause a nuEPSS 0.2%CVE-2024-8006MEDIUMNULL pointer dereference in libpcap before 1.10.5 with remote packet capture supportEPSS 0.2%CVE-2022-49692MEDIUMnet: phy: at803x: fix NULL pointer dereference on AR9331 PHYEPSS 0.2%CVE-2024-8235MEDIUMLibvirt: crash of virtinterfaced via virconnectlistinterfaces()EPSS 0.2%