Weaknesses of type CWE-476

2,336 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-53230MEDIUMcpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost()EPSS 0.2%CVE-2025-54409MEDIUMAIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS)EPSS 0.2%CVE-2024-56569MEDIUMftrace: Fix regression with module command in stack_trace_filterEPSS 0.2%CVE-2021-33714—A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a missing check forEPSS 0.2%CVE-2024-56575MEDIUMmedia: imx-jpeg: Ensure power suppliers be suspended before detach themEPSS 0.2%CVE-2024-47458MEDIUMBridge | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2022-34682MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a null-pEPSS 0.2%CVE-2022-48636HIGHs390/dasd: fix Oops in dasd_alias_get_start_dev due to missing pavgroupEPSS 0.2%CVE-2026-27217MEDIUMSubstance3D - Painter | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2026-27214MEDIUMSubstance3D - Painter | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2026-34704MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2024-38550MEDIUMASoC: kirkwood: Fix potential NULL dereferenceEPSS 0.2%CVE-2025-21669HIGHvsock/virtio: discard packets if the transport changesEPSS 0.2%CVE-2024-56579MEDIUMmedia: amphion: Set video drvdata before register video deviceEPSS 0.2%CVE-2022-49125MEDIUMdrm/sprd: fix potential NULL dereferenceEPSS 0.2%CVE-2021-32843MEDIUMHyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, `virtio.c` has EPSS 0.2%CVE-2022-3104MEDIUMAn issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks check of the return valuEPSS 0.2%CVE-2026-48429MEDIUMSubstance3D - Designer | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2026-27215MEDIUMSubstance3D - Painter | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2023-52607MEDIUMpowerpc/mm: Fix null-pointer dereference in pgtable_cache_addEPSS 0.2%