Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2025-45333HIGHberkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing moduEPSS 0.4%CVE-2025-62609MEDIUMMLX has Wild Pointer Dereference in load_gguf()EPSS 0.4%CVE-2024-12653MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x22040C null pointer dereferenceEPSS 0.4%CVE-2025-8033MEDIUMIncorrect JavaScript state machine for generatorsEPSS 0.4%CVE-2024-12657MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E000 null pointer dereferenceEPSS 0.4%CVE-2026-8252MEDIUMOpen5GS SMF smf_nsmf_handle_create_data_in_hsmf null pointer dereferenceEPSS 0.4%CVE-2025-65493HIGHNULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLSEPSS 0.4%CVE-2024-37820MEDIUMA nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation.EPSS 0.4%CVE-2024-39132MEDIUMA NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function VerifyCommaEPSS 0.4%CVE-2026-42183LOWArgo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)EPSS 0.4%CVE-2025-63648HIGHA NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackerEPSS 0.4%CVE-2022-2476—A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL =====================EPSS 0.4%CVE-2023-3012MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.4%CVE-2019-16230MEDIUMdrivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointeEPSS 0.4%CVE-2025-49694HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-29838HIGHWindows ExecutionContext Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-42902MEDIUMMemory Corruption vulnerability in SAP Netweaver AS ABAP and ABAP PlatformEPSS 0.4%CVE-2025-29901HIGHFile Station 5EPSS 0.4%CVE-2025-30267MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2025-30275MEDIUMQsync CentralEPSS 0.4%