Weaknesses of type CWE-476

2,336 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-36926MEDIUMpowerpc/pseries/iommu: LPAR panics during boot up with a frozen PEEPSS 0.2%CVE-2025-8224MEDIUMGNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereferenceEPSS 0.2%CVE-2025-65494HIGHNULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial EPSS 0.2%CVE-2025-12206MEDIUMKamailio rvalue.c rve_is_constant null pointer dereferenceEPSS 0.2%CVE-2026-0710HIGHSipp/sipp: sipp: denial of service and potential arbitrary code execution vulnerabilityEPSS 0.2%CVE-2024-56574MEDIUMmedia: ts2020: fix null-ptr-deref in ts2020_probe()EPSS 0.2%CVE-2025-69651MEDIUMGNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malfEPSS 0.2%CVE-2023-45935MEDIUMQt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is dEPSS 0.2%CVE-2025-11000MEDIUMOpen Babel PQSformat.cpp ReadMolecule null pointer dereferenceEPSS 0.2%CVE-2025-20080HIGHNull pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial EPSS 0.2%CVE-2023-52817MEDIUMdrm/amdgpu: Fix a null pointer access when the smc_rreg pointer is NULLEPSS 0.2%CVE-2026-70640HIGHllama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cppEPSS 0.2%CVE-2023-52814MEDIUMdrm/amdgpu: Fix potential null pointer derefernceEPSS 0.2%CVE-2025-27176MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2021-47369MEDIUMs390/qeth: fix NULL deref in qeth_clear_working_pool_list()EPSS 0.2%CVE-2025-27179MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2024-26612MEDIUMnetfs, fscache: Prevent Oops in fscache_put_cache()EPSS 0.2%CVE-2024-56593MEDIUMwifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw()EPSS 0.2%CVE-2024-23441MEDIUMVba32 Antivirus v3.36.0 - Denial of Service (DoS)EPSS 0.2%CVE-2024-26747MEDIUMusb: roles: fix NULL pointer issue when put module's referenceEPSS 0.2%