Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2025-0221MEDIUMIOBit Protected Folder IOCTL pffilter.sys 0x22200c null pointer dereferenceEPSS 0.4%CVE-2023-2871LOWFabulaTech USB for Remote Desktop IoControlCode 0x220408 null pointer dereferenceEPSS 0.4%CVE-2025-60019LOWGlib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via g_tls_bio_new_from_iostream() and g_tls_bio_new_from_datagram_based()EPSS 0.4%CVE-2023-31081MEDIUMAn issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vEPSS 0.4%CVE-2026-20727HIGHNull pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. UnEPSS 0.4%CVE-2026-17273MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.4%CVE-2025-0287MEDIUMCVE-2025-0287EPSS 0.4%CVE-2025-20262MEDIUMCisco Nexus 3000 and 9000 Series Switches Protocol Independent Multicast Version 6 Denial of Service VulnerabilityEPSS 0.4%CVE-2025-53589LOWQTS, QuTS heroEPSS 0.4%CVE-2026-17539MEDIUMRTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference EPSS 0.4%CVE-2024-39356HIGHNULL pointer dereference in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unaEPSS 0.4%CVE-2026-31931HIGHSuricata tls: null dereference in tls.alpn rule keywordEPSS 0.4%CVE-2026-44323MEDIUMfree5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)EPSS 0.4%CVE-2025-29547HIGHIn Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service because of a null pointer EPSS 0.4%CVE-2026-44317MEDIUMfree5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereferenceEPSS 0.4%CVE-2025-7700MEDIUMFfmpeg: null pointer dereference in ffmpeg als decoder (libavcodec/alsdec.c)EPSS 0.4%CVE-2023-52344MEDIUMIn modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosuEPSS 0.4%CVE-2025-53405LOWQTS, QuTS heroEPSS 0.3%CVE-2023-1631MEDIUMJiangMin Antivirus IOCTL kvcore.sys 0x222010 null pointer dereferenceEPSS 0.3%CVE-2025-53414LOWQTS, QuTS heroEPSS 0.3%