Fallos del tipo CWE-476

2331 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2025-20045HIGHBIG-IP SIP MRF VulnerabilityEPSS 0.4%CVE-2025-48722LOWQsync CentralEPSS 0.4%CVE-2025-70116MEDIUMA NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing desEPSS 0.4%CVE-2025-54147LOWQsync CentralEPSS 0.4%CVE-2025-47209LOWQsync CentralEPSS 0.4%CVE-2026-31256HIGHA null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the procesEPSS 0.4%CVE-2025-30266LOWQsync CentralEPSS 0.4%CVE-2025-52984HIGHJunos OS and Junos OS Evolved: When a static route points to a reject next-hop and a gNMI query for this route is processed, RPD crashesEPSS 0.4%CVE-2022-25733HIGHNull Pointer Dereference in MODEMEPSS 0.4%CVE-2022-25735HIGHNull Pointer Dereference in MODEMEPSS 0.4%CVE-2023-42754MEDIUMKernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()EPSS 0.4%CVE-2026-82803MEDIUMarmink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMENT null pointer dereferenceEPSS 0.4%CVE-2026-44316HIGHfree5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereferenceEPSS 0.4%CVE-2023-37028MEDIUMA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95EPSS 0.4%CVE-2025-7462MEDIUMArtifex GhostPDL New Output File Open Error gdevpdf.c pdf_ferror null pointer dereferenceEPSS 0.4%CVE-2025-50635HIGHA null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function ofEPSS 0.4%CVE-2025-62466HIGHWindows Client-Side Caching Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-57719MEDIUMlunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.EPSS 0.4%CVE-2026-32134MEDIUMNanoMQ: NULL Pointer Dereference Crash in tcptran_pipe_peer During Session RestoreEPSS 0.4%CVE-2026-40413HIGHWindows TCP/IP Denial of Service VulnerabilityEPSS 0.4%