Weaknesses of type CWE-476

2,338 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2023-2177MEDIUMA null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If stream_in allocation EPSS 0.2%CVE-2024-57925HIGHksmbd: fix a missing return value check bugEPSS 0.2%CVE-2024-56727MEDIUMocteontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.cEPSS 0.2%CVE-2023-41234MEDIUMNULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable deEPSS 0.2%CVE-2021-1115MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs, where an EPSS 0.2%CVE-2025-21941MEDIUMdrm/amd/display: Fix null check for pipe_ctx->plane_state in resource_build_scaling_paramsEPSS 0.2%CVE-2025-9817HIGHNULL Pointer Dereference in WiresharkEPSS 0.2%CVE-2021-47592MEDIUMnet: stmmac: fix tc flower deletion for VLAN priority Rx steeringEPSS 0.2%CVE-2022-50359MEDIUMmedia: cx88: Fix a null-ptr-deref bug in buffer_prepare()EPSS 0.2%CVE-2021-47471MEDIUMdrm: mxsfb: Fix NULL pointer dereference crash on unloadEPSS 0.2%CVE-2024-56726MEDIUMocteontx2-pf: handle otx2_mbox_get_rsp errors in cn10k.cEPSS 0.2%CVE-2024-47501MEDIUMJunos OS: MX304, MX with MPC10/11/LC9600, and EX9200 with EX9200-15C: In a VPLS or Junos Fusion scenario specific show commands cause FPCs to crashEPSS 0.2%CVE-2020-10066LOWIncorrect Error Handling in Bluetooth HCI coreEPSS 0.2%CVE-2026-21288MEDIUMIllustrator | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2025-21713MEDIUMpowerpc/pseries/iommu: Don't unset window if it was never setEPSS 0.2%CVE-2024-53154MEDIUMclk: clk-apple-nco: Add NULL check in applnco_probeEPSS 0.2%CVE-2024-50198MEDIUMiio: light: veml6030: fix IIO device retrieval from embedded deviceEPSS 0.2%CVE-2024-56774MEDIUMbtrfs: add a sanity check for btrfs root in btrfs_search_slot()EPSS 0.2%CVE-2024-57933MEDIUMgve: guard XSK operations on the existence of queuesEPSS 0.2%CVE-2024-47439MEDIUMSubstance3D - Painter | NULL Pointer Dereference (CWE-476)EPSS 0.2%