Fallos del tipo CWE-476

2335 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2026-82926MEDIUMNULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aEPSS 0.1%CVE-2026-3776MEDIUMNull pointer dereference in Foxit PDF Editor/Reader when accessing stamp annotationEPSS 0.1%CVE-2026-17574MEDIUMNULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type TagEPSS 0.1%CVE-2025-20675MEDIUMIn wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execEPSS 0.1%CVE-2026-42442LOWNanaZip: Null-pointer dereference in NanaZip UFS parser when root inode is a symlinkEPSS 0.1%CVE-2025-20676MEDIUMIn wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execEPSS 0.1%CVE-2025-10823MEDIUMaxboe fio options.c str_buffer_pattern_cb null pointer dereferenceEPSS 0.1%CVE-2025-23300MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocaEPSS 0.1%CVE-2025-60007MEDIUMJunos OS: A specifically crafted 'show chassis' command causes chassisd to crashEPSS 0.1%CVE-2026-24805MEDIUMMishandles certain out-of-memory conditions in visualfc/liteide via liteidex/src/3rdparty/libvterm/src moduleEPSS 0.1%CVE-2025-45525LOWA NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a lightweight syntax highliEPSS 0.1%CVE-2023-53292MEDIUMblk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_noneEPSS 0.1%CVE-2025-39895MEDIUMsched: Fix sched_numa_find_nth_cpu() if mask offlineEPSS 0.1%CVE-2026-6845MEDIUMBinutils: binutils: denial of service via crafted elf fileEPSS 0.1%CVE-2023-53380MEDIUMmd/raid10: fix null-ptr-deref of mreplace in raid10_sync_requestEPSS 0.1%CVE-2025-62815MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.astEPSS 0.1%CVE-2026-21338MEDIUMSubstance3D - Designer | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2023-53296MEDIUMsctp: check send stream number after wait_for_sndbufEPSS 0.1%CVE-2026-21350MEDIUMAfter Effects | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2023-53245MEDIUMscsi: storvsc: Fix handling of virtual Fibre Channel timeoutsEPSS 0.1%