Weaknesses of type CWE-476

2,337 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-34703MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2021-32844MEDIUMHyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, ` vi_pci_write`EPSS 0.2%CVE-2025-21669HIGHvsock/virtio: discard packets if the transport changesEPSS 0.2%CVE-2026-34704MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2026-34662MEDIUMIllustrator | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2026-27218MEDIUMSubstance3D - Painter | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2024-50224MEDIUMspi: spi-fsl-dspi: Fix crash when not using GPIO chip selectEPSS 0.2%CVE-2021-32843MEDIUMHyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, `virtio.c` has EPSS 0.2%CVE-2022-3110MEDIUMAn issue was discovered in the Linux kernel through 5.16-rc6. _rtw_init_xmit_priv in drivers/staging/r8188eu/core/rtw_xmit.c lacks check of EPSS 0.2%CVE-2023-4385MEDIUMKernel: jfs: null pointer dereference in dbfree()EPSS 0.2%CVE-2024-56577MEDIUMmedia: mtk-jpeg: Fix null-ptr-deref during unload moduleEPSS 0.2%CVE-2025-21682HIGHeth: bnxt: always recalculate features after XDP clearing, fix null-derefEPSS 0.2%CVE-2023-0190MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a NULL pointer dereference may lead to denial oEPSS 0.2%CVE-2025-1371MEDIUMGNU elfutils eu-read readelf.c handle_dynamic_symtab null pointer dereferenceEPSS 0.2%CVE-2021-47230MEDIUMKVM: x86: Immediately reset the MMU context when the SMM flag is clearedEPSS 0.2%CVE-2022-3078—An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack of free after allocaEPSS 0.2%CVE-2025-12207MEDIUMKamailio Grammar Rule cfg.y yyerror_at null pointer dereferenceEPSS 0.2%CVE-2021-29530LOWInvalid validation in `SparseMatrixSparseCholesky`EPSS 0.2%CVE-2026-20878HIGHNull pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of serEPSS 0.2%CVE-2024-50147MEDIUMnet/mlx5: Fix command bitmask initializationEPSS 0.2%