Fallos del tipo CWE-476

2324 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2024-1914MEDIUMAn attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vEPSS 0.7%CVE-2026-1682MEDIUMFree5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereferenceEPSS 0.7%CVE-2025-14180HIGHNULL Pointer Dereference in PDO quotingEPSS 0.7%CVE-2024-36831MEDIUMA NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attacEPSS 0.7%CVE-2022-1649HIGHNull pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in radareorg/radare2EPSS 0.7%CVE-2022-36013MEDIUMNull-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef` in TensorFlowEPSS 0.7%CVE-2022-1382MEDIUMNULL Pointer Dereference in radareorg/radare2EPSS 0.7%CVE-2022-27497HIGHNull pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allEPSS 0.7%CVE-2022-4843MEDIUMNULL Pointer Dereference in radareorg/radare2EPSS 0.7%CVE-2024-53217HIGHNFSD: Prevent NULL dereference in nfsd4_process_cb_update()EPSS 0.7%CVE-2024-34088HIGHIn FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In caseEPSS 0.7%CVE-2024-23327HIGHCrash in proxy protocol when command type of LOCAL in EnvoyEPSS 0.7%CVE-2022-49664HIGHtipc: move bc link creation back to tipc_node_createEPSS 0.7%CVE-2026-0731MEDIUMTOTOLINK WA1200 HTTP Request cstecgi.cgi null pointer dereferenceEPSS 0.7%CVE-2024-34508MEDIUMdcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.EPSS 0.7%CVE-2026-53719MEDIUMEnvoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorizationEPSS 0.7%CVE-2024-25197MEDIUMOpen Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCuEPSS 0.7%CVE-2023-46049MEDIUMLLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a crafted .o file)EPSS 0.7%CVE-2021-33572LOWDenial-of-Service (DoS) VulnerabilityEPSS 0.7%CVE-2024-43357HIGHJavaScript specification issue may lead to type confusion and pointer dereference in implementationsEPSS 0.7%