Fallos del tipo CWE-476

2321 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2022-0632MEDIUMNULL Pointer Dereference in mruby/mrubyEPSS 0.8%CVE-2023-27336HIGHSofting edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service VulnerabilityEPSS 0.8%CVE-2022-0326MEDIUMNULL Pointer Dereference in mruby/mrubyEPSS 0.8%CVE-2024-10280HIGHTenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereferenceEPSS 0.8%CVE-2026-28389HIGHPossible NULL Dereference When Processing CMS KeyAgreeRecipientInfoEPSS 0.8%CVE-2026-28390HIGHPossible NULL Dereference When Processing CMS KeyTransportRecipientInfoEPSS 0.8%CVE-2024-12002MEDIUMTenda FH451/FH1201/FH1202/FH1206 GetIPTV websReadEvent null pointer dereferenceEPSS 0.8%CVE-2024-52546MEDIUMLorex 2K Indoor Wi-Fi Security Camera - Null pointer dereferenceEPSS 0.8%CVE-2020-15209MEDIUMNull pointer dereference in tensorflow-liteEPSS 0.8%CVE-2025-53477HIGHApache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layerEPSS 0.8%CVE-2023-51391HIGHMicrium OS Network uC-HTTP server header parsing invalid pointer dereference vulnerabilityEPSS 0.8%CVE-2024-35878MEDIUMof: module: prevent NULL pointer dereference in vsnprintf()EPSS 0.8%CVE-2024-11588MEDIUMAVL-DiTEST-DiagDev libdoip DoIPConnection.cpp reactOnReceivedTcpMessage null pointer dereferenceEPSS 0.8%CVE-2026-66303MEDIUMSkype for Business and Lync Denial of Service VulnerabilityEPSS 0.8%CVE-2022-21739MEDIUMNull pointer dereference in TensorFlowEPSS 0.8%CVE-2022-23577MEDIUMNull-dereference in TensorflowEPSS 0.8%CVE-2020-28163MEDIUMlibdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that hasEPSS 0.8%CVE-2024-33345MEDIUMD-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi, which allows remoteEPSS 0.8%CVE-2024-31030CRITICALAn issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentially disclose informaEPSS 0.8%CVE-2024-20446HIGHCisco NX-OS Software DHCPv6 Relay Agent Denial of Service VulnerabilityEPSS 0.8%