Fallos del tipo CWE-476

2333 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2023-33088HIGHNULL pointer dereference in WLAN FirmwareEPSS 0.2%CVE-2026-32776MEDIUMlibexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.EPSS 0.2%CVE-2025-20071MEDIUMNULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via locaEPSS 0.2%CVE-2026-57225LOWSuricata datasets: NULL pointer dereference in JSON/NDJSON dataset loadingEPSS 0.2%CVE-2026-47271MEDIUMpam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentication process crashEPSS 0.2%CVE-2025-23346LOWNVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereference. A successful exEPSS 0.2%CVE-2023-53228MEDIUMdrm/amdgpu: drop redundant sched job cleanup when cs is abortedEPSS 0.2%CVE-2026-32778LOWlibexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.EPSS 0.2%CVE-2023-53220MEDIUMmedia: az6007: Fix null-ptr-deref in az6007_i2c_xfer()EPSS 0.2%CVE-2022-50402MEDIUMdrivers/md/md-bitmap: check the return value of md_bitmap_get_counter()EPSS 0.2%CVE-2023-53304MEDIUMnetfilter: nft_set_rbtree: fix overlap expiration walkEPSS 0.2%CVE-2023-53275MEDIUMALSA: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync()EPSS 0.2%CVE-2023-53280MEDIUMscsi: qla2xxx: Remove unused nvme_ls_waitq wait queueEPSS 0.2%CVE-2023-53223MEDIUMdrm/msm/dsi: Add missing check for alloc_ordered_workqueueEPSS 0.2%CVE-2023-53277MEDIUMwifi: iwl3945: Add missing check for create_singlethread_workqueueEPSS 0.2%CVE-2023-53239MEDIUMdrm/msm/mdp5: Add check for kzallocEPSS 0.2%CVE-2022-50380MEDIUMmm: /proc/pid/smaps_rollup: fix no vma's null-derefEPSS 0.2%CVE-2022-49733HIGHALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNCEPSS 0.2%CVE-2023-53210MEDIUMmd/raid5-cache: fix null-ptr-deref for r5l_flush_stripe_to_raid()EPSS 0.2%CVE-2022-41597LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%