Weaknesses of type CWE-476

2,337 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2023-1095MEDIUMIn nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction object. nft_trans_desEPSS 0.2%CVE-2022-49869MEDIUMbnxt_en: Fix possible crash in bnxt_hwrm_set_coal()EPSS 0.2%CVE-2021-29592MEDIUMNull pointer dereference in TFLite's `Reshape` operatorEPSS 0.2%CVE-2025-23136MEDIUMthermal: int340x: Add NULL check for adevEPSS 0.2%CVE-2022-41972LOWContiki-NG contains NULL Pointer Dereference in BLE L2CAP moduleEPSS 0.2%CVE-2024-58011MEDIUMplatform/x86: int3472: Check for adev == NULLEPSS 0.2%CVE-2024-34138MEDIUMAdobe Illustrator CGM File Parsing Division By zeroEPSS 0.2%CVE-2024-50225HIGHbtrfs: fix error propagation of split biosEPSS 0.2%CVE-2026-50673HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2024-58012MEDIUMASoC: SOF: Intel: hda-dai: Ensure DAI widget is valid during paramsEPSS 0.2%CVE-2025-21857MEDIUMnet/sched: cls_api: fix error handling causing NULL dereferenceEPSS 0.2%CVE-2024-56646MEDIUMipv6: avoid possible NULL deref in modify_prefix_route()EPSS 0.2%CVE-2025-21637HIGHsctp: sysctl: udp_port: avoid using current->nsproxyEPSS 0.2%CVE-2025-14957MEDIUMWebAssembly Binaryen IRBuilder wasm-ir-builder.cpp makeLocalTee null pointer dereferenceEPSS 0.2%CVE-2025-21833MEDIUMiommu/vt-d: Avoid use of NULL after WARN_ON_ONCEEPSS 0.2%CVE-2025-21847MEDIUMASoC: SOF: stream-ipc: Check for cstream nullity in sof_ipc_msg_data()EPSS 0.2%CVE-2025-21901HIGHRDMA/bnxt_re: Add sanity checks on rdev validityEPSS 0.2%CVE-2025-7209MEDIUM9fans plan9port x509.c value_decode null pointer dereferenceEPSS 0.2%CVE-2022-21815MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NUEPSS 0.2%CVE-2022-4127MEDIUMA NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw toEPSS 0.2%