Fallos del tipo CWE-476

2331 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2026-46334HIGHOpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloningEPSS 0.5%CVE-2026-48139HIGHNULL pointer dereference vulnerability in NI grpc-device data moniker serviceEPSS 0.5%CVE-2022-3153MEDIUMNULL Pointer Dereference in vim/vimEPSS 0.5%CVE-2018-1130MEDIUMLinux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dccp/output.c in that EPSS 0.5%CVE-2023-37456The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS <EPSS 0.5%CVE-2020-3552HIGHCisco Aironet Access Points Ethernet Wired Clients Denial of Service VulnerabilityEPSS 0.5%CVE-2025-0430HIGHBelledonne Communications Linphone-Desktop NULL Pointer DereferenceEPSS 0.5%CVE-2026-23948MEDIUMFreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()EPSS 0.5%CVE-2025-54146LOWQsync CentralEPSS 0.5%CVE-2025-53598LOWQsync CentralEPSS 0.5%CVE-2024-3184MEDIUMMultiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when compiled with the ME_GOAEPSS 0.5%CVE-2021-33798MEDIUMA null pointer dereference was found in libpano13, version libpano13-2.9.20. The flow allows attackers to cause a denial of service and poteEPSS 0.5%CVE-2025-54148LOWQsync CentralEPSS 0.5%CVE-2018-5449A NULL Pointer Dereference issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application does EPSS 0.5%CVE-2026-55204HIGHHAProxy - NULL Pointer Dereference in hpack_dht_insert FunctionEPSS 0.5%CVE-2022-2874MEDIUMNULL Pointer Dereference in vim/vimEPSS 0.5%CVE-2024-2551HIGHPAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted PacketEPSS 0.5%CVE-2024-57435MEDIUMIn macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereferencEPSS 0.5%CVE-2024-45239HIGHAn issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync oEPSS 0.5%CVE-2026-77692HIGHUnauthenticated remote crash of named via a single DoH SIG(0) requestEPSS 0.5%