Fallos del tipo CWE-476

2329 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2017-2586LOWA null pointer dereference vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to craEPSS 1.2%CVE-2026-42764HIGHNULL Pointer Dereference in QUIC Server Initial Packet HandlingEPSS 1.2%CVE-2024-50318HIGHA null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.EPSS 1.2%CVE-2024-50317HIGHA null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.EPSS 1.2%CVE-2020-35495There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cEPSS 1.2%CVE-2026-69744HIGHWindows Kerberos Denial of Service VulnerabilityEPSS 1.1%CVE-2021-40785MEDIUMAdobe Premiere Elements Null Pointer Dereference Application denial-of-serviceEPSS 1.1%CVE-2021-40796MEDIUMAdobe Premiere Pro Null Pointer Dereference Application denial-of-serviceEPSS 1.1%CVE-2021-40789MEDIUMAdobe Premiere Elements Null Pointer Dereference Application denial-of-serviceEPSS 1.1%CVE-2021-40762MEDIUMAdobe Character Animator NULL Pointer Dereference Application denial-of-serviceEPSS 1.1%CVE-2021-42263MEDIUMAdobe Premiere Pro Null Pointer Dereference Application denial-of-serviceEPSS 1.1%CVE-2021-40768MEDIUMAdobe Character Animator NULL Pointer Dereference Application denial-of-serviceEPSS 1.1%CVE-2021-40788MEDIUMAdobe Premiere Elements Null Pointer Dereference Application denial-of-serviceEPSS 1.1%CVE-2021-42264MEDIUMAdobe Premiere Pro Null Pointer Dereference Application denial-of-serviceEPSS 1.1%CVE-2022-24810MEDIUMnet-snmp: A malformed OID in a SET to the nsVacmAccessTable can cause a NULL pointer dereference.EPSS 1.1%CVE-2020-1995MEDIUMPAN-OS: Management server rasmgr denial of serviceEPSS 1.1%CVE-2020-35496There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file tEPSS 1.1%CVE-2026-72939MEDIUMWindows Routing and Remote Access Service (RRAS) Denial of Service VulnerabilityEPSS 1.1%CVE-2026-50366MEDIUMWindows Active Directory Domain Services Denial of Service VulnerabilityEPSS 1.1%CVE-2026-57976MEDIUMWindows Active Directory Domain Services Denial of Service VulnerabilityEPSS 1.1%