Fallos del tipo CWE-476

2331 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2021-20196A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commandsEPSS 0.5%CVE-2022-36011MEDIUMNull dereference on MLIR on empty function attributes in TensorFlowEPSS 0.5%CVE-2025-47808MEDIUMIn GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle fileEPSS 0.5%CVE-2024-25177HIGHLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of SeEPSS 0.5%CVE-2022-36000MEDIUMNull dereference on MLIR on empty function attributes in TensorFlowEPSS 0.5%CVE-2023-53335HIGHRDMA/cxgb4: Fix potential null-ptr-deref in pass_establish()EPSS 0.5%CVE-2025-59668HIGHMultiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafted certain UDP packetEPSS 0.5%CVE-2023-46867MEDIUMIn International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a NULL pointer derefeEPSS 0.5%CVE-2026-23952MEDIUMImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image loadEPSS 0.5%CVE-2026-10852MEDIUMWebsphere Application Server is Affected By a Denial of ServiceEPSS 0.5%CVE-2017-12153A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This fEPSS 0.5%CVE-2025-45835HIGHA null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function ofEPSS 0.5%CVE-2025-47213MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-48728MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-27917HIGHAn issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOSEPSS 0.5%CVE-2023-33089HIGHNULL Pointer Dereference in WLAN FirmwareEPSS 0.5%CVE-2025-48729MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2023-2609HIGHNULL Pointer Dereference in vim/vimEPSS 0.5%CVE-2025-66720HIGHNull pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId.EPSS 0.5%CVE-2025-48727MEDIUMQTS, QuTS heroEPSS 0.5%