Fallos del tipo CWE-476

2330 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2026-50366MEDIUMWindows Active Directory Domain Services Denial of Service VulnerabilityEPSS 1.1%CVE-2023-45667MEDIUMNull pointer dereference because of an uninitialized variable in stb_imageEPSS 1.1%CVE-2021-21057MEDIUMAcrobat Reader DC Invalid Memory Read Due To An Uninitialized PointerEPSS 1.1%CVE-2022-24808MEDIUMnet-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereferenceEPSS 1.1%CVE-2026-72949HIGHWindows SMB Server Network Transport Driver (srvnet.sys) Denial of Service VulnerabilityEPSS 1.1%CVE-2025-11846MEDIUMA null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9EPSS 1.1%CVE-2023-3316MEDIUMA NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.EPSS 1.1%CVE-2024-50609HIGHAn issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one canEPSS 1.1%CVE-2024-50608HIGHAn issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and porEPSS 1.1%CVE-2021-33717A vulnerability has been identified in JT2Go (All versions < V13.2.0.1), Teamcenter Visualization (All versions < V13.2.0.1). When parsing sEPSS 1.1%CVE-2020-1656HIGHJunos OS: When a DHCPv6 Relay-Agent is configured upon receipt of a specific DHCPv6 client message, Remote Code Execution may occur.EPSS 1.1%CVE-2022-23589MEDIUMNull pointer dereference in Grappler's `IsConstant` in TensorflowEPSS 1.1%CVE-2024-47542MEDIUMGHSL-2024-235: GStreamer ID3v2 parser out-of-bounds read and NULL-pointer dereferenceEPSS 1.1%CVE-2022-24809MEDIUMnet-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereferenceEPSS 1.1%CVE-2023-46427CRITICALAn issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial EPSS 1.1%CVE-2021-23191A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may resuEPSS 1.1%CVE-2025-14769HIGHipfw denial of serviceEPSS 1.1%CVE-2021-26927A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of servEPSS 1.1%CVE-2017-7511poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.EPSS 1.1%CVE-2023-28484MEDIUMIn libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This ocEPSS 1.1%