Fallos del tipo CWE-476

2335 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2025-46711MEDIUMGPU DDK - NULL Pointer dereference occurs in LockHandle on bridge entry when connection misusedEPSS 0.1%CVE-2026-44638LOWlibsixel: NULL pointer dereferenceEPSS 0.1%CVE-2024-53024HIGHNULL Pointer Dereference in DisplayEPSS 0.1%CVE-2026-15171MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2026-24918MEDIUMAddress read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-26690LOWcommunication dsoftbus has a NULL pointer vulnerabilityEPSS 0.1%CVE-2026-43864LOWmutt before 2.3.2 has a show_sig_summary NULL pointer dereference.EPSS 0.1%CVE-2026-25110LOWSensors_medical_sensor has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2025-9548MEDIUMA potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticatedEPSS 0.1%CVE-2024-0035HIGHIn onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null checkEPSS 0.1%CVE-2021-25462LOWNULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.EPSS 0.1%CVE-2026-10199MEDIUMAssimp glTF2Asset.h LazyDict null pointer dereferenceEPSS 0.1%CVE-2021-25458LOWNULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.EPSS 0.1%CVE-2025-61143MEDIUMlibtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.EPSS 0.1%CVE-2026-1288MEDIUMRFA File Parsing Vulnerability in Autodesk RevitEPSS 0.1%CVE-2026-10197MEDIUMAssimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereferenceEPSS 0.1%CVE-2026-10198MEDIUMAssimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereferenceEPSS 0.1%CVE-2026-10298MEDIUMggml-org whisper.cpp ggml.c whisper_model_load null pointer dereferenceEPSS 0.1%CVE-2025-7018MEDIUMAvira antivirus engine null pointer dereference when scanning a malformed PE fileEPSS 0.1%CVE-2023-43541HIGHNULL Pointer Dereference in Windows GraphicsEPSS 0.1%