Weaknesses of type CWE-476

2,336 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2021-47369MEDIUMs390/qeth: fix NULL deref in qeth_clear_working_pool_list()EPSS 0.2%CVE-2024-23441MEDIUMVba32 Antivirus v3.36.0 - Denial of Service (DoS)EPSS 0.2%CVE-2024-2204MEDIUMZemana AntiLogger v2.74.204.664 - Denial of Service (DoS)EPSS 0.2%CVE-2024-0430MEDIUMIObit Malware Fighter v11.0.0.1274 - Denial of Service (DoS)EPSS 0.2%CVE-2024-26747MEDIUMusb: roles: fix NULL pointer issue when put module's referenceEPSS 0.2%CVE-2024-58052MEDIUMdrm/amdgpu: Fix potential NULL pointer dereference in atomctrl_get_smc_sclk_range_tableEPSS 0.2%CVE-2025-70070MEDIUMAn issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()EPSS 0.2%CVE-2024-53180MEDIUMALSA: pcm: Add sanity NULL check for the default mmap fault handlerEPSS 0.2%CVE-2023-37039MEDIUMA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95EPSS 0.2%CVE-2024-36888MEDIUMworkqueue: Fix selection of wake_cpu in kick_pool()EPSS 0.2%CVE-2024-32637MEDIUMA vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), TeamceEPSS 0.2%CVE-2023-46343MEDIUMIn the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.EPSS 0.2%CVE-2025-21846MEDIUMacct: perform last write from workqueueEPSS 0.2%CVE-2024-36941MEDIUMwifi: nl80211: don't free NULL coalescing ruleEPSS 0.2%CVE-2024-50223MEDIUMsched/numa: Fix the potential null pointer dereference in task_numa_work()EPSS 0.2%CVE-2024-53230MEDIUMcpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost()EPSS 0.2%CVE-2025-39755MEDIUMstaging: gpib: Fix cb7210 pcmcia OopsEPSS 0.2%CVE-2025-54409MEDIUMAIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS)EPSS 0.2%CVE-2021-33715—A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a race condition coEPSS 0.2%CVE-2024-53231MEDIUMcpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw()EPSS 0.2%