Weaknesses of type CWE-476

2,337 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-49332MEDIUMscsi: lpfc: Address NULL pointer dereference after starget_to_rport()EPSS 0.2%CVE-2025-22054MEDIUMarcnet: Add NULL check in com20020pci_probe()EPSS 0.2%CVE-2023-45920MEDIUMXfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expectEPSS 0.2%CVE-2023-25523LOW NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the nvdisasm binary file, where an attacker may cause a NULL pointeEPSS 0.2%CVE-2026-48097HIGHNexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command ExecutionEPSS 0.2%CVE-2024-36897MEDIUMdrm/amd/display: Atom Integrated System Info v2_2 for DCN35EPSS 0.2%CVE-2022-31615MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause EPSS 0.2%CVE-2024-1443MEDIUMMSI Afterburner v4.6.5.16370 - Denial of ServiceEPSS 0.2%CVE-2022-49529MEDIUMdrm/amdgpu/pm: fix the null pointer while the smu is disabledEPSS 0.2%CVE-2025-8586MEDIUMlibav MPEG File Parser utils.c ff_seek_frame_binary null pointer dereferenceEPSS 0.2%CVE-2025-21689MEDIUMUSB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb()EPSS 0.2%CVE-2024-0072LOW NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a EPSS 0.2%CVE-2025-21904MEDIUMcaif_virtio: fix wrong pointer check in cfv_probe()EPSS 0.2%CVE-2021-47464HIGHaudit: fix possible null-pointer dereference in audit_filter_rulesEPSS 0.2%CVE-2023-52462—bpf: fix check for attempt to corrupt spilled pointerEPSS 0.2%CVE-2021-47257MEDIUMnet: ieee802154: fix null deref in parse dev addrEPSS 0.2%CVE-2022-3115MEDIUMAn issue was discovered in the Linux kernel through 5.16-rc6. malidp_crtc_reset in drivers/gpu/drm/arm/malidp_crtc.c lacks check of the retuEPSS 0.2%CVE-2025-6858MEDIUMHDF5 H5Centry.c H5C__flush_single_entry null pointer dereferenceEPSS 0.2%CVE-2025-21670MEDIUMvsock/bpf: return early if transport is not assignedEPSS 0.2%CVE-2024-26978—serial: max310x: fix NULL pointer dereference in I2C instantiationEPSS 0.2%