Weaknesses of type CWE-476

2,338 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2025-21901HIGHRDMA/bnxt_re: Add sanity checks on rdev validityEPSS 0.2%CVE-2025-21649MEDIUMnet: hns3: fix kernel crash when 1588 is sent on HIP08 devicesEPSS 0.2%CVE-2021-3463MEDIUMA null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause sysEPSS 0.2%CVE-2025-7209MEDIUM9fans plan9port x509.c value_decode null pointer dereferenceEPSS 0.2%CVE-2024-35940MEDIUMpstore/zone: Add a null pointer check to the psz_kmsg_readEPSS 0.2%CVE-2022-21815MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NUEPSS 0.2%CVE-2023-52939MEDIUMmm: memcg: fix NULL pointer in mem_cgroup_track_foreign_dirty_slowpath()EPSS 0.2%CVE-2023-1583MEDIUMA NULL pointer dereference was found in io_file_bitmap_get in io_uring/filetable.c in the io_uring sub-component in the Linux Kernel. When fEPSS 0.2%CVE-2023-52938MEDIUMusb: typec: ucsi: Don't attempt to resume the ports before they existEPSS 0.2%CVE-2024-26277MEDIUMA vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All vEPSS 0.2%CVE-2023-1587MEDIUMAvast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue was fixed with Avast aEPSS 0.2%CVE-2025-21852MEDIUMnet: Add rx_skb of kfree_skb to raw_tp_null_args[].EPSS 0.2%CVE-2022-50354HIGHdrm/amdkfd: Fix kfd_process_device_init_vm error handlingEPSS 0.2%CVE-2024-56629MEDIUMHID: wacom: fix when get product name maybe null pointerEPSS 0.2%CVE-2021-29583LOWHeap buffer overflow and undefined behavior in `FusedBatchNorm`EPSS 0.2%CVE-2025-8584MEDIUMlibav AVI File Parser buffer.c av_buffer_unref null pointer dereferenceEPSS 0.2%CVE-2024-58021MEDIUMHID: winwing: Add NULL check in winwing_init_led()EPSS 0.2%CVE-2022-48908MEDIUMnet: arcnet: com20020: Fix null-ptr-deref in com20020pci_probe()EPSS 0.2%CVE-2024-36011MEDIUMBluetooth: HCI: Fix potential null-ptr-derefEPSS 0.2%CVE-2025-22066MEDIUMASoC: imx-card: Add NULL check in imx_card_probe()EPSS 0.2%