Weaknesses of type CWE-476

2,337 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-26978—serial: max310x: fix NULL pointer dereference in I2C instantiationEPSS 0.2%CVE-2025-21670MEDIUMvsock/bpf: return early if transport is not assignedEPSS 0.2%CVE-2022-3114MEDIUMAn issue was discovered in the Linux kernel through 5.16-rc6. imx_register_uart_clocks in drivers/clk/imx/clk.c lacks check of the return vaEPSS 0.2%CVE-2023-52631MEDIUMfs/ntfs3: Fix an NULL dereference bugEPSS 0.2%CVE-2025-21675MEDIUMnet/mlx5: Clear port select structure when fail to createEPSS 0.2%CVE-2024-56670MEDIUMusb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointerEPSS 0.2%CVE-2023-52994MEDIUMacpi: Fix suspend with Xen PVEPSS 0.2%CVE-2024-50132HIGHtracing/probes: Fix MAX_TRACE_ARGS limit handlingEPSS 0.2%CVE-2024-53233MEDIUMunicode: Fix utf8_load() error pathEPSS 0.2%CVE-2024-58058MEDIUMubifs: skip dumping tnc tree when zroot is nullEPSS 0.2%CVE-2025-21666MEDIUMvsock: prevent null-ptr-deref in vsock_*[has_data|has_space]EPSS 0.2%CVE-2024-56661MEDIUMtipc: fix NULL deref in cleanup_bearer()EPSS 0.2%CVE-2023-52508MEDIUMnvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()EPSS 0.2%CVE-2022-49484MEDIUMmt76: mt7915: fix possible NULL pointer dereference in mt7915_mac_fill_rx_vectorEPSS 0.2%CVE-2026-0156HIGHIn checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remoteEPSS 0.2%CVE-2025-21775MEDIUMcan: ctucanfd: handle skb allocation failureEPSS 0.2%CVE-2025-22018MEDIUMatm: Fix NULL pointer dereferenceEPSS 0.2%CVE-2024-48873MEDIUMwifi: rtw89: check return value of ieee80211_probereq_get() for RNREPSS 0.2%CVE-2023-52869MEDIUMpstore/platform: Add check for kstrdupEPSS 0.2%CVE-2021-25674—A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the system could cause a DeniEPSS 0.2%