Fallos del tipo CWE-476

2335 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2022-47468MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47467MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47465MEDIUMIn vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.EPSS 0.1%CVE-2022-47466MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-48444MEDIUMIn telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution EPSS 0.1%CVE-2022-48443MEDIUMIn telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution EPSS 0.1%CVE-2022-48445MEDIUMIn telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution EPSS 0.1%CVE-2025-31711MEDIUMIn cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additEPSS 0.1%CVE-2026-24929MEDIUMOut-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2022-48442MEDIUMIn dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution priEPSS 0.1%CVE-2025-21433MEDIUMNULL Pointer Dereference in SPS-HLOSEPSS 0.1%CVE-2025-59606HIGHNULL Pointer Dereference in HLOSEPSS 0.1%CVE-2025-59604HIGHNULL Pointer Dereference in SPS ApplicationsEPSS 0.1%CVE-2026-100890MEDIUMTrusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode null pointer dereferenceEPSS —CVE-2026-100895MEDIUMTrusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereferenceEPSS —