Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2025-30267MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2025-49686HIGHWindows TCP/IP Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-78222HIGHNGINX ngx_http_js_module vulnerabilityEPSS 0.4%CVE-2025-22921MEDIUMFFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.EPSS 0.4%CVE-2025-24251MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS SonoEPSS 0.4%CVE-2022-1201HIGHNULL Pointer Dereference in mrb_vm_exec with super in mruby/mrubyEPSS 0.4%CVE-2026-6666MEDIUMPgBouncer crash in kill_pool_logins_server_errorEPSS 0.4%CVE-2023-1186LOWFabulaTech Webcam for Remote Desktop IOCTL ftwebcam.sys 0x222018 null pointer dereferenceEPSS 0.4%CVE-2026-67304HIGHFreeRDP before 3.29.0 NULL Dereference via smartcard cleanupEPSS 0.4%CVE-2024-56430LOWOpenFHE through 1.2.3 has a NULL pointer dereference in BinFHEContext::EvalFloor in lib/binfhe-base-scheme.cpp.EPSS 0.4%CVE-2024-27229HIGHIn ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lEPSS 0.4%CVE-2026-4652HIGHRemote denial of service via null pointer dereferenceEPSS 0.4%CVE-2024-44101HIGHthere is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service witEPSS 0.4%CVE-2020-25639—A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way thEPSS 0.4%CVE-2025-20755MEDIUMIn Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has cEPSS 0.4%CVE-2026-32216MEDIUMWindows Redirected Drive Buffering System Denial of Service VulnerabilityEPSS 0.4%CVE-2026-33283MEDIUMElla Core panics on malformed ULNASTransport Message without a Request TypeEPSS 0.4%CVE-2026-24411HIGHiccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlSegmentedCurve::ToXml()EPSS 0.4%CVE-2026-92626HIGHControl iD iDSecure Unauthenticated Denial of ServiceEPSS 0.4%CVE-2025-20647MEDIUMIn Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connectedEPSS 0.4%