Weaknesses of type CWE-476

2,337 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-34137MEDIUMAdobe Illustrator 2024 CGM File Parsing Null Pointer DereferenceEPSS 0.2%CVE-2025-21783MEDIUMgpiolib: Fix crash on error in gpiochip_get_ngpios()EPSS 0.2%CVE-2024-56660MEDIUMnet/mlx5: DR, prevent potential error pointer dereferenceEPSS 0.2%CVE-2022-3106MEDIUMAn issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the EPSS 0.2%CVE-2024-56667MEDIUMdrm/i915: Fix NULL pointer dereference in capture_engineEPSS 0.2%CVE-2024-50255MEDIUMBluetooth: hci: fix null-ptr-deref in hci_read_supported_codecsEPSS 0.2%CVE-2021-47312MEDIUMnetfilter: nf_tables: Fix dereference of null pointer flowEPSS 0.2%CVE-2025-49567MEDIUMIllustrator | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2023-51744LOWA vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), TeamcenEPSS 0.2%CVE-2021-1116MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a NULL pointer dereference in EPSS 0.2%CVE-2021-1122MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lEPSS 0.2%CVE-2024-32941MEDIUMNULL pointer dereference for some Intel(R) MLC software before version v3.11b may allow an authenticated user to potentially enable denial oEPSS 0.2%CVE-2023-52870MEDIUMclk: mediatek: clk-mt6765: Add check for mtk_alloc_clk_dataEPSS 0.2%CVE-2025-21170MEDIUMSubstance3D - Modeler | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2025-21774MEDIUMcan: rockchip: rkcanfd_handle_rx_fifo_overflow_int(): bail out if skb cannot be allocatedEPSS 0.2%CVE-2022-34675MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in the Virtual GPU Manager, where it does not check the return value from a null-poEPSS 0.2%CVE-2025-23330MEDIUMNVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer dereference. A successfulEPSS 0.2%CVE-2024-50298MEDIUMnet: enetc: allocate vf_state during PF probesEPSS 0.2%CVE-2024-57989MEDIUMwifi: mt76: mt7925: fix NULL deref check in mt7925_change_vif_linksEPSS 0.2%CVE-2024-57987MEDIUMBluetooth: btrtl: check for NULL in btrtl_setup_realtek()EPSS 0.2%