Fallos del tipo CWE-476

2331 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2024-12655MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x220420 null pointer dereferenceEPSS 0.5%CVE-2024-12660MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E018 null pointer dereferenceEPSS 0.5%CVE-2025-53010LOWMaterialX's unchecked nodeGraph->getOutput return is vulnerable to NULL Pointer DereferenceEPSS 0.5%CVE-2025-53412LOWFile Station 5EPSS 0.5%CVE-2022-35965MEDIUMSegfault in `LowerBound` and `UpperBound` in TensorFlowEPSS 0.5%CVE-2025-62463MEDIUMDirectX Graphics Kernel Denial of Service VulnerabilityEPSS 0.5%CVE-2025-62465MEDIUMDirectX Graphics Kernel Denial of Service VulnerabilityEPSS 0.5%CVE-2026-24404HIGHiccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType()EPSS 0.5%CVE-2025-29889MEDIUMFile Station 5EPSS 0.5%CVE-2025-29875HIGHFile Station 5EPSS 0.5%CVE-2026-25168MEDIUMWindows Graphics Component Denial of Service VulnerabilityEPSS 0.5%CVE-2025-30262MEDIUMQsync CentralEPSS 0.5%CVE-2025-14953LOWOpen5GS FAR-ID handler.c ogs_pfcp_handle_create_pdr null pointer dereferenceEPSS 0.5%CVE-2026-50032HIGHNULL Pointer Dereference in MZ Automation libIEC61850EPSS 0.5%CVE-2025-30263MEDIUMQsync CentralEPSS 0.5%CVE-2025-29878MEDIUMFile Station 5EPSS 0.5%CVE-2026-9716HIGHCWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuEPSS 0.5%CVE-2026-57434LOWNokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classesEPSS 0.5%CVE-2025-29886MEDIUMFile Station 5EPSS 0.5%CVE-2025-29874MEDIUMFile Station 5EPSS 0.5%