Fallos del tipo CWE-476

2331 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2025-66769HIGHA NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA pacEPSS 0.4%CVE-2026-8619HIGHUnauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600EPSS 0.4%CVE-2026-22693MEDIUMNull Pointer Dereference in SubtableUnicodesCache::create leading to DoSEPSS 0.4%CVE-2026-0968LOWLibssh: libssh: denial of service due to malformed sftp messageEPSS 0.4%CVE-2026-30072HIGHA NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crEPSS 0.4%CVE-2022-4285MEDIUMAn illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may resulEPSS 0.4%CVE-2026-17510HIGHCrypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attributeEPSS 0.4%CVE-2024-41164HIGHBIG-IP MPTCP vulnerabilityEPSS 0.4%CVE-2024-54130CRITICALSegmentation Fault in `forwardBundle` Function of ION-DTN BPv7 When Destination EID is `dtn:none` (public)EPSS 0.4%CVE-2026-45541HIGHESF-IDF: Remote Null Pointer Dereference in WebSocket ServerEPSS 0.4%CVE-2025-65563HIGHA denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.EPSS 0.4%CVE-2024-11148HIGHOpenBSD httpd(8) null dereferenceEPSS 0.4%CVE-2025-21676HIGHnet: fec: handle page_pool_dev_alloc_pages errorEPSS 0.4%CVE-2022-1263A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged loEPSS 0.4%CVE-2023-40546MEDIUMShim: out-of-bounds read printing error messagesEPSS 0.4%CVE-2026-15690LOWopen62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereferenceEPSS 0.4%CVE-2023-41274MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.4%CVE-2025-53141HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-53154HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-61668HIGH@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous userEPSS 0.4%