Weaknesses of type CWE-476

2,333 results

Desreferência de nulo autenticada remota

A aplicação não valida corretamente se um ponteiro ou referência é nulo antes de usá-lo, permitindo que um usuário autenticado remotamente forneça entrada que causa uma desreferência de nulo. O resultado é um crash da aplicação ou, em cenários mais graves, execução de código não prevista, dependendo de como a memória é tratada.

Example

Um endpoint de API autenticada que busca um usuário por ID, mas não verifica se o resultado da busca é nulo. Um atacante autenticado fornece um ID inexistente, o código tenta acessar propriedades do resultado nulo e a aplicação falha ou se comporta de forma imprevista.

How to mitigate

Sempre validar retornos de funções que podem ser nulos antes de acessar seus membros ou métodos. Use assertions, verificações explícitas (if obj != null) ou mecanismos de linguagem como optional/Maybe types para forçar o tratamento seguro de valores nulos.

CVE-2026-3389MEDIUMSquirrel sqstdrex.cpp sqstd_rex_newnode null pointer dereferenceEPSS 0.2%CVE-2025-21982MEDIUMpinctrl: nuvoton: npcm8xx: Add NULL check in npcm8xx_gpio_fwEPSS 0.2%CVE-2025-22002MEDIUMnetfs: Call `invalidate_cache` only if implementedEPSS 0.2%CVE-2025-21989MEDIUMdrm/amd/display: fix missing .is_two_pixels_per_containerEPSS 0.2%CVE-2023-1382MEDIUMA data race flaw was found in the Linux kernel, between where con is allocated and con->sock is set. This issue leads to a NULL pointer dereEPSS 0.2%CVE-2025-8534LOWlibtiff tiff2ps tiff2ps.c PS_Lvl2page null pointer dereferenceEPSS 0.2%CVE-2026-21502MEDIUMNULL Pointer Dereference in iccDEV XML Tag ParserEPSS 0.2%CVE-2024-56668MEDIUMiommu/vt-d: Fix qi_batch NULL pointer with nested parent domainEPSS 0.2%CVE-2024-56666MEDIUMdrm/amdkfd: Dereference null return valueEPSS 0.2%CVE-2026-21497MEDIUMNULL Pointer Dereference in iccDEV Unknown Tag ParserEPSS 0.2%CVE-2023-53356MEDIUMusb: gadget: u_serial: Add null pointer check in gserial_suspendEPSS 0.2%CVE-2026-21496MEDIUMNULL Pointer Dereference in iccDEV Signature ParserEPSS 0.2%CVE-2026-21498MEDIUMNULL Pointer Dereference in iccDEV XML Calculator ParserEPSS 0.2%CVE-2023-33121LOWA vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), TeamcenEPSS 0.2%CVE-2024-58076MEDIUMclk: qcom: gcc-sm6350: Add missing parent_map for two clocksEPSS 0.2%CVE-2026-21503MEDIUMiccDEV has Undefined Behavior - Null Pointer Passed to memcpy() in CIccTagSparseMatrixArrayEPSS 0.2%CVE-2026-21499MEDIUMNULL Pointer Dereference in iccDEV XML ParserEPSS 0.2%CVE-2026-86547MEDIUMmrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTEREPSS 0.2%CVE-2024-50281HIGHKEYS: trusted: dcp: fix NULL dereference in AEAD crypto operationEPSS 0.2%CVE-2026-21506MEDIUMiccDEV is Vulnerable to Null Pointer Dereference in CIccProfileXml::ParseBasic() Leading to Denial of ServiceEPSS 0.2%