Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2021-29541LOWNull pointer dereference in `StringNGrams`EPSS 0.2%CVE-2026-3392MEDIUMFascinatedBox lily lily_emitter.c eval_tree null pointer dereferenceEPSS 0.2%CVE-2024-50122MEDIUMPCI: Hold rescan lock while adding devices during host probeEPSS 0.2%CVE-2024-50277MEDIUMdm: fix a crash if blk_alloc_disk failsEPSS 0.2%CVE-2024-22524MEDIUMdnspod-sr 0dfbd37 is vulnerable to buffer overflow.EPSS 0.2%CVE-2024-50118MEDIUMbtrfs: reject ro->rw reconfiguration if there are hard ro requirementsEPSS 0.2%CVE-2025-60473MEDIUMA NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allowEPSS 0.2%CVE-2026-90828MEDIUMGNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereferenceEPSS 0.2%CVE-2024-53069MEDIUMfirmware: qcom: scm: fix a NULL-pointer dereferenceEPSS 0.2%CVE-2024-58022MEDIUMmailbox: th1520: Fix a NULL vs IS_ERR() bugEPSS 0.2%CVE-2021-41215MEDIUMNull pointer exception in `DeserializeSparse`EPSS 0.2%CVE-2021-41217MEDIUMNull pointer exception when `Exit` node is not preceded by `Enter` opEPSS 0.2%CVE-2023-53366MEDIUMblock: be a bit more careful in checking for NULL bdev while pollingEPSS 0.2%CVE-2026-3665MEDIUMxlnt-community xlnt XLSX File xlsx_consumer.cpp read_office_document null pointer dereferenceEPSS 0.2%CVE-2026-3387MEDIUMwren-lang wren wren_compiler.c getByteCountForArguments null pointer dereferenceEPSS 0.2%CVE-2025-22006MEDIUMnet: ethernet: ti: am65-cpsw: Fix NAPI registration sequenceEPSS 0.2%CVE-2025-22002MEDIUMnetfs: Call `invalidate_cache` only if implementedEPSS 0.2%CVE-2025-21990MEDIUMdrm/amdgpu: NULL-check BO's backing store when determining GFX12 PTE flagsEPSS 0.2%CVE-2025-21989MEDIUMdrm/amd/display: fix missing .is_two_pixels_per_containerEPSS 0.2%CVE-2026-32249MEDIUMNFA regex engine NULL pointer dereference affects Vim < 9.2.0137EPSS 0.2%