Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2022-4842MEDIUMA flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to cEPSS 0.2%CVE-2022-31613HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where any local user can cause a null-pointer derefEPSS 0.2%CVE-2024-1096MEDIUMTwister Antivirus v8.17 - Denial of ServiceEPSS 0.2%CVE-2022-49925MEDIUMRDMA/core: Fix null-ptr-deref in ib_core_cleanup()EPSS 0.2%CVE-2023-31018MEDIUMCVEEPSS 0.2%CVE-2023-3357MEDIUMA NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the systeEPSS 0.2%CVE-2026-3146MEDIUMlibvips matrixload.c vips_foreign_load_matrix_header null pointer dereferenceEPSS 0.2%CVE-2025-31180MEDIUMGnuplot: gnuplot segmentation fault on canvas_textEPSS 0.2%CVE-2025-31178MEDIUMGnuplot: gnuplot segmentation fault on getannotatestringEPSS 0.2%CVE-2023-3358MEDIUMA null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash EPSS 0.2%CVE-2025-31176MEDIUMGnuplot: gnuplot segmentation fault on plot3d_pointsEPSS 0.2%CVE-2025-31179MEDIUMGnuplot: gnuplot segmentation fault on xstrftimeEPSS 0.2%CVE-2026-70639MEDIUMllama.cpp b1886–b7445 Null Pointer Dereference DoS via llama-android.cppEPSS 0.2%CVE-2025-31181MEDIUMGnuplot: gnuplot segmentation fault on x11_graphicsEPSS 0.2%CVE-2024-0079MEDIUMCVEEPSS 0.2%CVE-2022-49904MEDIUMnet, neigh: Fix null-ptr-deref in neigh_table_clear()EPSS 0.2%CVE-2026-88384MEDIUMOpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-typEPSS 0.2%CVE-2022-49863MEDIUMcan: af_can: fix NULL pointer dereference in can_rx_register()EPSS 0.2%CVE-2026-44512MEDIUMONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)EPSS 0.2%CVE-2025-31163MEDIUMfig2dev segmentation faultEPSS 0.2%