Weaknesses of type CWE-476

2,337 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2024-57987MEDIUMBluetooth: btrtl: check for NULL in btrtl_setup_realtek()EPSS 0.2%CVE-2022-34675MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in the Virtual GPU Manager, where it does not check the return value from a null-poEPSS 0.2%CVE-2023-3220MEDIUMAn issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check oEPSS 0.2%CVE-2024-50298MEDIUMnet: enetc: allocate vf_state during PF probesEPSS 0.2%CVE-2025-21774MEDIUMcan: rockchip: rkcanfd_handle_rx_fifo_overflow_int(): bail out if skb cannot be allocatedEPSS 0.2%CVE-2025-21170MEDIUMSubstance3D - Modeler | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2024-56711MEDIUMdrm/panel: himax-hx83102: Add a check to prevent NULL pointer dereferenceEPSS 0.2%CVE-2025-21636MEDIUMsctp: sysctl: plpmtud_probe_interval: avoid using current->nsproxyEPSS 0.2%CVE-2025-54270MEDIUMAnimate | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2024-50160MEDIUMALSA: hda/cs8409: Fix possible NULL dereferenceEPSS 0.2%CVE-2025-21644MEDIUMdrm/xe: Fix tlb invalidation when wedgingEPSS 0.2%CVE-2024-50156MEDIUMdrm/msm: Avoid NULL dereference in msm_disp_state_print_regs()EPSS 0.2%CVE-2024-56544MEDIUMudmabuf: change folios array from kmalloc to kvmallocEPSS 0.2%CVE-2024-53199MEDIUMASoC: imx-audmix: Add NULL check in imx_audmix_probeEPSS 0.2%CVE-2022-49875MEDIUMbpftool: Fix NULL pointer dereference when pin {PROG, MAP, LINK} without FILEEPSS 0.2%CVE-2025-8835MEDIUMJasPer Image Color Space Conversion jas_image.c jas_image_chclrspc null pointer dereferenceEPSS 0.2%CVE-2022-41972LOWContiki-NG contains NULL Pointer Dereference in BLE L2CAP moduleEPSS 0.2%CVE-2022-49869MEDIUMbnxt_en: Fix possible crash in bnxt_hwrm_set_coal()EPSS 0.2%CVE-2024-56702MEDIUMbpf: Mark raw_tp arguments with PTR_MAYBE_NULLEPSS 0.2%CVE-2021-29592MEDIUMNull pointer dereference in TFLite's `Reshape` operatorEPSS 0.2%