Fallos del tipo CWE-476

2335 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2026-47337LOWNULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediationEPSS 0.1%CVE-2026-47327LOWNULL pointer dereference in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2025-39820MEDIUMdrm/msm/dpu: Add a null ptr check for dpu_encoder_needs_modesetEPSS 0.1%CVE-2025-25217LOWarkui_ace_enginehas a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2026-21364MEDIUMSubstance3D - Painter | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2025-0009MEDIUMA NULL pointer dereference in AMD Crash Defender could allow an attacker to write a NULL output to a log file potentially resulting in a sysEPSS 0.1%CVE-2026-21363MEDIUMSubstance3D - Painter | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2025-1698LOWNull pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial oEPSS 0.1%CVE-2025-39878MEDIUMceph: fix crash after fscrypt_encrypt_pagecache_blocks() errorEPSS 0.1%CVE-2025-39892MEDIUMASoC: soc-core: care NULL dirver name on snd_soc_lookup_component_nolocked()EPSS 0.1%CVE-2025-39856MEDIUMnet: ethernet: ti: am65-cpsw-nuss: Fix null pointer dereference for ndevEPSS 0.1%CVE-2025-39858MEDIUMeth: mlx4: Fix IS_ERR() vs NULL check bug in mlx4_en_create_rx_ringEPSS 0.1%CVE-2025-39879MEDIUMceph: always call ceph_shift_unused_folios_left()EPSS 0.1%CVE-2025-39814MEDIUMice: fix NULL pointer dereference in ice_unplug_aux_dev() on resetEPSS 0.1%CVE-2025-39875MEDIUMigb: Fix NULL pointer dereference in ethtool loopback testEPSS 0.1%CVE-2025-39887MEDIUMtracing/osnoise: Fix null-ptr-deref in bitmap_parselist()EPSS 0.1%CVE-2025-11156MEDIUMImproper Service Loading Vulnerability in Netskope Endpoint DLP DriverEPSS 0.1%CVE-2026-58561MEDIUMNull pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-58560MEDIUMNull pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-46711MEDIUMGPU DDK - NULL Pointer dereference occurs in LockHandle on bridge entry when connection misusedEPSS 0.1%