Fallos del tipo CWE-476

2328 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2021-33572LOWDenial-of-Service (DoS) VulnerabilityEPSS 0.7%CVE-2025-66646LOWRIOT-OS has NULL pointer dereference in gnrc_ipv6_ext_frag_reassEPSS 0.7%CVE-2022-1283MEDIUMNULL Pointer Dereference in r_bin_ne_get_entrypoints function in radareorg/radare2EPSS 0.7%CVE-2024-43357HIGHJavaScript specification issue may lead to type confusion and pointer dereference in implementationsEPSS 0.7%CVE-2026-0918HIGHNull Pointer Dereference in Tapo SmartCam HTTP Service on TP-Link Tapo C220 & C520WSEPSS 0.7%CVE-2021-47486HIGHriscv, bpf: Fix potential NULL dereferenceEPSS 0.7%CVE-2026-2062MEDIUMOpen5GS PGW S5U Address sgwc_sxa_handle_session_modification_response null pointer dereferenceEPSS 0.7%CVE-2023-34398HIGHMercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archEPSS 0.7%CVE-2023-34400HIGHMercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. In case of parsing file, service try to definEPSS 0.7%CVE-2025-6395MEDIUMGnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()EPSS 0.7%CVE-2023-43279MEDIUMNull Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewriEPSS 0.7%CVE-2024-24783MEDIUMVerify panics on certificates with an unknown public key algorithm in crypto/x509EPSS 0.7%CVE-2026-47220HIGHEnvoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log formatEPSS 0.7%CVE-2026-62309HIGHCoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoSEPSS 0.7%CVE-2024-23083MEDIUMTime4J Base v5.9.3 was discovered to contain a NullPointerException via the component net.time4j.format.internal.FormatUtils::useDefaultWeekEPSS 0.7%CVE-2026-29785HIGHNATS Server panic via malicious compression on leafnode portEPSS 0.7%CVE-2023-38670MEDIUMNull pointer dereference in paddle.flipEPSS 0.7%CVE-2022-3113MEDIUMAn issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.EPSS 0.7%CVE-2022-22232HIGHSRX Series: If Unified Threat Management (UTM) Enhanced Content Filtering (CF) is enabled and specific traffic is processed the PFE will crashEPSS 0.7%CVE-2022-43495MEDIUMAn abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.EPSS 0.7%