Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2023-33109HIGHNULL Pointer Dereference in WLAN FirmwareEPSS 0.3%CVE-2026-15891HIGHNULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gatewayEPSS 0.3%CVE-2022-29201MEDIUMMissing validation in `QuantizedConv2D` results in undefined behavior in TensorFlowEPSS 0.3%CVE-2025-47111MEDIUMAcrobat Reader | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2025-52585HIGHBIG-IP Client SSL profile vulnerabilityEPSS 0.3%CVE-2022-48509—Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulEPSS 0.3%CVE-2026-33903MEDIUMElla Core panics when processing a crafted NGAP LocationReport messageEPSS 0.3%CVE-2024-10037MEDIUMA vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crEPSS 0.3%CVE-2022-34683MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a nuEPSS 0.3%CVE-2026-77489HIGHWindows Biometric Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50315HIGHWindows Image Acquisition Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-53592LOWQTS, QuTS heroEPSS 0.3%CVE-2025-44013LOWQTS, QuTS heroEPSS 0.3%CVE-2025-54334HIGHAn issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL PointEPSS 0.3%CVE-2025-54326HIGHAn issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in theEPSS 0.3%CVE-2025-54332HIGHAn issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Dereference of profiler.noEPSS 0.3%CVE-2026-24716LOWQTS, QuTS heroEPSS 0.3%CVE-2026-45151LOWNanoMQ: NULL Pointer DereferenceEPSS 0.3%CVE-2025-62850MEDIUMQuTS heroEPSS 0.3%CVE-2022-43589MEDIUMA null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Filter 20.0.8317. A spEPSS 0.3%