Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2025-53596LOWQTS, QuTS heroEPSS 0.3%CVE-2022-41843MEDIUMAn issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-3892EPSS 0.3%CVE-2025-58120HIGHBIG-IP Next (CNF, SPK, and Kubernetes) vulnerabilityEPSS 0.3%CVE-2025-52426LOWQTS, QuTS heroEPSS 0.3%CVE-2025-52430LOWQTS, QuTS heroEPSS 0.3%CVE-2026-57873HIGHGV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEEE8021x_upload.cgi)EPSS 0.3%CVE-2025-61960HIGHBIG-IP APM portal access vulnerabilityEPSS 0.3%CVE-2025-53590LOWQTSEPSS 0.3%CVE-2025-52431LOWQTS, QuTS heroEPSS 0.3%CVE-2024-24446MEDIUMAn uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.3%CVE-2026-72582HIGHfastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery EndpointEPSS 0.3%CVE-2025-63929HIGHA null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple threads enqueue elementEPSS 0.3%CVE-2024-52296MEDIUMlibosdp has a null pointer deref in osdp_reply_nameEPSS 0.3%CVE-2024-6062MEDIUMGPAC MP4Box load_text.c swf_svg_add_iso_sample null pointer dereferenceEPSS 0.3%CVE-2026-67288HIGHFreeRDP before 3.29.0 Denial of Service via smartcard cacheEPSS 0.3%CVE-2026-91954HIGHFreeRDP before 3.31.0 NULL Pointer Dereference via NSCodecEPSS 0.3%CVE-2025-55659MEDIUMA NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial EPSS 0.3%CVE-2026-16702MEDIUMIBM® Db2® federated server could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereferenceEPSS 0.3%CVE-2025-45332HIGHvkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leadinEPSS 0.3%CVE-2026-26457HIGHccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg() function when procesEPSS 0.3%