Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2022-43589MEDIUMA null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Filter 20.0.8317. A spEPSS 0.3%CVE-2022-37290MEDIUMGNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.EPSS 0.3%CVE-2022-43590MEDIUMA null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback technologies CBFS Filter EPSS 0.3%CVE-2022-43588MEDIUMA null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Filter 20.0.8317. A spEPSS 0.3%CVE-2024-6063MEDIUMGPAC MP4Box dmx_m2ts.c m2tsdmx_on_event null pointer dereferenceEPSS 0.3%CVE-2026-19012MEDIUMAuthenticated denial of service in Consul Enterprise-to-Community Edition downgrade pathEPSS 0.3%CVE-2023-5586MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.3%CVE-2023-2872MEDIUMFlexiHub IoControlCode fusbhub.sys 0x220088 null pointer dereferenceEPSS 0.3%CVE-2023-2875MEDIUMeScan Antivirus IoControlCode PROCOBSRVESX.SYS 0x22E008u null pointer dereferenceEPSS 0.3%CVE-2023-24847HIGHNULL pointer Dereference in ModemEPSS 0.3%CVE-2022-49532MEDIUMdrm/virtio: fix NULL pointer dereference in virtio_gpu_conn_get_modesEPSS 0.3%CVE-2025-40833HIGHThe affected devices contain a null pointer dereference vulnerability while processing specially crafted IPv4 requests. This could allow an EPSS 0.3%CVE-2023-43522HIGHNULL Pointer Dereference in WLAN FirmwareEPSS 0.3%CVE-2022-47094HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pidEPSS 0.3%CVE-2025-15156MEDIUMomec-project UPF PFCP Session Establishment Request messages_session.go handleSessionEstablishmentRequest null pointer dereferenceEPSS 0.3%CVE-2022-1789—With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlEPSS 0.3%CVE-2024-53224HIGHRDMA/mlx5: Move events notifier registration to be after device registrationEPSS 0.3%CVE-2025-8402MEDIUMNil pointer dereference in bulk import crashes serverEPSS 0.3%CVE-2024-12654MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x220408 null pointer dereferenceEPSS 0.3%CVE-2023-6622MEDIUMKernel: null pointer dereference vulnerability in nft_dynset_init()EPSS 0.3%