Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2023-2166MEDIUMA null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may not be initialized in EPSS 0.2%CVE-2023-25510LOWNVIDIA CUDA Toolkit SDK for Linux and Windows contains a NULL pointer dereference in cuobjdump, where a local user running the tool against EPSS 0.2%CVE-2025-21685MEDIUMplatform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev raceEPSS 0.2%CVE-2025-22052MEDIUMstaging: gpib: Fix Oops after disconnect in ni_usbEPSS 0.2%CVE-2025-22051MEDIUMstaging: gpib: Fix Oops after disconnect in agilent usbEPSS 0.2%CVE-2025-21940MEDIUMdrm/amdkfd: Fix NULL Pointer Dereference in KFD queueEPSS 0.2%CVE-2022-49758MEDIUMreset: uniphier-glue: Fix possible null-ptr-derefEPSS 0.2%CVE-2023-53011MEDIUMnet: stmmac: enable all safety features by defaultEPSS 0.2%CVE-2025-47807MEDIUMIn GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitEPSS 0.2%CVE-2025-4003MEDIUMRefindPlusRepo RefindPlus RP_ApfsIo.c InternalApfsTranslateBlock null pointer dereferenceEPSS 0.2%CVE-2025-4002MEDIUMRefindPlusRepo RefindPlus BootLog.c GetDebugLogFile null pointer dereferenceEPSS 0.2%CVE-2025-27170MEDIUMIllustrator | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2022-50353MEDIUMmmc: wmt-sdmmc: fix return value check of mmc_add_host()EPSS 0.2%CVE-2025-30300MEDIUMAdobe Framemaker | NULL Pointer Dereference (CWE-476)EPSS 0.2%CVE-2021-29516LOWNull pointer dereference via invalid Ragged TensorsEPSS 0.2%CVE-2023-53352MEDIUMdrm/ttm: check null pointer before accessing when swappingEPSS 0.2%CVE-2022-50369MEDIUMdrm/vkms: Fix null-ptr-deref in vkms_release()EPSS 0.2%CVE-2026-54084MEDIUMWazuh agent enrollment NULL pointer dereference via malformed manager responseEPSS 0.2%CVE-2025-22009MEDIUMregulator: dummy: force synchronous probingEPSS 0.2%CVE-2024-56580MEDIUMmedia: qcom: camss: fix error path on configuration of power domainsEPSS 0.2%