Fallos del tipo CWE-476

2335 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2026-32849MEDIUMNetBSD Signed Integer Overflow in cryptodev_op via cryptodev.cEPSS 0.2%CVE-2024-6157MEDIUMAn attacker who successfully exploited these vulnerabilities could cause the robot to stop. A vulnerability exists in the PROFINET stack EPSS 0.2%CVE-2022-41593LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2026-10670MEDIUMUser-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifierEPSS 0.2%CVE-2022-41598LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41595LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41592LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41594LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41603LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2025-6398MEDIUMA null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a speciaEPSS 0.1%CVE-2025-63745MEDIUMA NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binarEPSS 0.1%CVE-2024-0086MEDIUMCVEEPSS 0.1%CVE-2024-58073MEDIUMdrm/msm/dpu: check dpu_plane_atomic_print_state() for valid ssppEPSS 0.1%CVE-2024-58066MEDIUMclk: mmp: pxa1908-apbcp: Fix a NULL vs IS_ERR() checkEPSS 0.1%CVE-2024-58065MEDIUMclk: mmp: pxa1908-apbc: Fix NULL vs IS_ERR() checkEPSS 0.1%CVE-2023-53289MEDIUMmedia: bdisp: Add missing check for create_workqueueEPSS 0.1%CVE-2023-53384MEDIUMwifi: mwifiex: avoid possible NULL skb pointer dereferenceEPSS 0.1%CVE-2025-8735MEDIUMGNU cflow Lexer c.c yylex null pointer dereferenceEPSS 0.1%CVE-2023-53440HIGHnilfs2: fix sysfs interface lifetimeEPSS 0.1%CVE-2024-58067MEDIUMclk: mmp: pxa1908-mpmu: Fix a NULL vs IS_ERR() checkEPSS 0.1%