Fallos del tipo CWE-476

2331 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2025-47205MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2023-1264MEDIUMNULL Pointer Dereference in vim/vimEPSS 0.4%CVE-2022-38928HIGHXPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.EPSS 0.4%CVE-2025-14309HIGHNULL Pointer Dereference vulnerability in ravynsoft ravynos.This issue affects ravynos: through 0.5.2.EPSS 0.4%CVE-2024-24442HIGHA NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackersEPSS 0.4%CVE-2025-22490MEDIUMFile Station 5EPSS 0.4%CVE-2025-29873MEDIUMFile Station 5EPSS 0.4%CVE-2025-29876MEDIUMFile Station 5EPSS 0.4%CVE-2025-29877MEDIUMFile Station 5EPSS 0.4%CVE-2023-2908MEDIUMLibtiff: null pointer dereference in tif_dir.cEPSS 0.4%CVE-2026-75439HIGHAn issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF componentEPSS 0.4%CVE-2026-76905HIGHkin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoSEPSS 0.4%CVE-2026-55209CRITICALresdata insufficiently validates untrusted GRDECL filesEPSS 0.4%CVE-2025-41433HIGHBIG-IP SIP ALG profile vulnerabilityEPSS 0.4%CVE-2026-17500MEDIUMggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereferenceEPSS 0.4%CVE-2026-33262MEDIUMInsufficient validation of cookie replyEPSS 0.4%CVE-2026-42285HIGHGoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)EPSS 0.4%CVE-2024-24194HIGHrobdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-parse.c.EPSS 0.4%CVE-2025-30670MEDIUMZoom Workplace Apps for Windows - Null PointerEPSS 0.4%CVE-2025-30645HIGHJunos OS: SRX Series: Transmission of specific control traffic sent out of a DS-Lite tunnel results in flowd crashEPSS 0.4%