Fallos del tipo CWE-476

2333 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2026-39956MEDIUMjq: Missing runtime type checks for _strindices lead to crash and limited memory disclosureEPSS 0.2%CVE-2025-33197MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereference. A successful expEPSS 0.2%CVE-2021-37689HIGHNull pointer dereference in TensorFlow Lite MLIR optimizationsEPSS 0.2%CVE-2024-45476MEDIUMA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2025-20677MEDIUMIn Bluetooth driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User exeEPSS 0.2%CVE-2026-48985MEDIUMpam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remote FieldEPSS 0.2%CVE-2025-15571MEDIUMckolivas lrzip stream.c ucompthread null pointer dereferenceEPSS 0.2%CVE-2025-20673MEDIUMIn wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execEPSS 0.2%CVE-2024-31078LOWBluetooth Service has a use after free vulnerabilityEPSS 0.2%CVE-2022-49895MEDIUMcxl/region: Fix decoder allocation crashEPSS 0.2%CVE-2026-1990MEDIUMoatpp Type.hpp ObjectWrapper null pointer dereferenceEPSS 0.2%CVE-2022-50415MEDIUMparisc: led: Fix potential null-ptr-deref in start_task()EPSS 0.2%CVE-2024-35215MEDIUMNULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 aEPSS 0.2%CVE-2022-49894MEDIUMcxl/region: Fix region HPA ordering validationEPSS 0.2%CVE-2022-49876MEDIUMwifi: mac80211: fix general-protection-fault in ieee80211_subif_start_xmit()EPSS 0.2%CVE-2023-53364MEDIUMregulator: da9063: better fix null deref with partial DTEPSS 0.2%CVE-2025-6496MEDIUMHTACG tidy-html5 parser.c InsertNodeAsParent null pointer dereferenceEPSS 0.2%CVE-2022-49848MEDIUMphy: qcom-qmp-combo: fix NULL-deref on runtime resumeEPSS 0.2%CVE-2024-56568MEDIUMiommu/arm-smmu: Defer probe of clients after smmu device boundEPSS 0.2%CVE-2026-86056MEDIUMNotepad++: Null pointer dereference in NPPM_SAVESESSION message handler causes crash (DoS)EPSS 0.2%