Fallos del tipo CWE-476

2331 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2024-25560HIGHTMM VulnerabilityEPSS 0.5%CVE-2024-48615HIGHNull Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchivEPSS 0.5%CVE-2026-31973MEDIUMNULL pointer dereference in samtools cram-sizeEPSS 0.5%CVE-2022-26097MEDIUMNull pointer dereference vulnerability in parser_unknown_property function in libsimba library prior to SMR Apr-2022 Release 1 allows out ofEPSS 0.5%CVE-2022-26096MEDIUMNull pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds writEPSS 0.5%CVE-2022-27567MEDIUMNull pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds writEPSS 0.5%CVE-2022-26094MEDIUMNull pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds writEPSS 0.5%CVE-2022-26095MEDIUMNull pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds writEPSS 0.5%CVE-2022-26099MEDIUMNull pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds readEPSS 0.5%CVE-2026-33600MEDIUMNull pointer dereference in RPZ transferEPSS 0.5%CVE-2022-26093MEDIUMNull pointer dereference vulnerability in parser_irot function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds writEPSS 0.5%CVE-2025-54163LOWFile Station 5EPSS 0.5%CVE-2024-36972HIGHaf_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock.EPSS 0.5%CVE-2025-32909MEDIUMLibsoup: null pointer dereference on libsoup through function "sniff_mp4" in soup-content-sniffer.cEPSS 0.5%CVE-2024-35492HIGHCesanta Mongoose commit b316989 was discovered to contain a NULL pointer dereference via the scpy function at src/fmt.c. This vulnerability EPSS 0.5%CVE-2025-4478MEDIUMGnome-remote-desktop: freerdp: unauthenticated rdp packet causes segfault in freerdp leading to denial of serviceEPSS 0.5%CVE-2022-1725MEDIUMNULL Pointer Dereference in vim/vimEPSS 0.5%CVE-2024-20426HIGHA vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) SoftwEPSS 0.5%CVE-2026-16353CRITICALInvalid pointer in the DOM: Bindings (WebIDL) componentEPSS 0.5%CVE-2025-53011LOWMaterialX is Vulnerable to NULL Pointer Dereference due to Unchecked implGraphOutputEPSS 0.5%