Fallos del tipo CWE-476

2335 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2026-84396MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2024-5198LOWOpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driveEPSS 0.1%CVE-2025-15535MEDIUMnicbarker clay clay.h Clay__MeasureTextCached null pointer dereferenceEPSS 0.1%CVE-2025-21998MEDIUMfirmware: qcom: uefisecapp: fix efivars registration raceEPSS 0.1%CVE-2026-76881MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2023-53401MEDIUMmm: kmem: fix a NULL pointer dereference in obj_stock_flush_required()EPSS 0.1%CVE-2025-14841MEDIUMOFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereferenceEPSS 0.1%CVE-2024-9484MEDIUMAn null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformEPSS 0.1%CVE-2026-47335MEDIUMNULL pointer dereference in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2025-39906HIGHdrm/amd/display: remove oem i2c adapter on finishEPSS 0.1%CVE-2024-9483MEDIUMUninitialized variable in digital signiture verification may crash the applicationEPSS 0.1%CVE-2026-19411LOWShim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns nullEPSS 0.1%CVE-2025-9337MEDIUMA null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, whiEPSS 0.1%CVE-2026-10659MEDIUMNULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resumeEPSS 0.1%CVE-2026-13070MEDIUMImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process TerminationEPSS 0.1%CVE-2025-8090MEDIUMVulnerability in the QNX Neutrino Kernel impacts the QNX Software Development Platform and QNX OS for SafetyEPSS 0.1%CVE-2025-60495MEDIUMA segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows atEPSS 0.1%CVE-2024-32666MEDIUMNULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denialEPSS 0.1%CVE-2026-9759MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2025-33237MEDIUMNVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference issue. A successful eEPSS 0.1%