Fallos del tipo CWE-476

2335 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2025-7007HIGHNull pointer dereference in Avast Antivirus on macOS (16.0.0) or Linux (3.0.3)EPSS 0.1%CVE-2025-13425LOWDenial of Service in OSV-SCALIBREPSS 0.1%CVE-2025-46592MEDIUMNull pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availabEPSS 0.1%CVE-2025-60477MEDIUMA NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before EPSS 0.1%CVE-2024-56188MEDIUMthere is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with no additional execuEPSS 0.1%CVE-2024-47290MEDIUMInput validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2023-33036HIGHNULL Pointer Dereference in HypervisorEPSS 0.1%CVE-2021-25491LOWA vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.EPSS 0.1%CVE-2026-20771MEDIUMNull pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow aEPSS 0.1%CVE-2025-27701MEDIUMIn the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_arraEPSS 0.1%CVE-2026-20914MEDIUMNull pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow EPSS 0.1%CVE-2026-20064MEDIUMA vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device tEPSS 0.1%CVE-2024-23357MEDIUMNULL Pointer Dereference in HLOSEPSS 0.1%CVE-2025-53170MEDIUMNull pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vulnerability may affectEPSS 0.1%CVE-2022-48231MEDIUMIn soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privEPSS 0.1%CVE-2022-48241MEDIUMIn telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution EPSS 0.1%CVE-2022-44447MEDIUMIn wlan driver, there is a possible null pointer dereference issue due to a missing bounds check. This could lead to local denial of serviceEPSS 0.1%CVE-2024-29751MEDIUMIn asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information EPSS 0.1%CVE-2026-17009MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2024-27232MEDIUMIn asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclEPSS 0.1%