Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2024-12654MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x220408 null pointer dereferenceEPSS 0.3%CVE-2019-10140MEDIUMA vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a deEPSS 0.3%CVE-2022-29205MEDIUMSegfault due to missing support for quantized types in TensorFlowEPSS 0.3%CVE-2024-12662MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E040 null pointer dereferenceEPSS 0.3%CVE-2026-21689MEDIUMiccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cppEPSS 0.3%CVE-2023-45925—GNU Midnight Commander 4.8.29-146-g299d9a2fb was discovered to contain a NULL pointer dereference via the function x_error_handler() at tty/EPSS 0.3%CVE-2020-35505—A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurEPSS 0.3%CVE-2023-1628MEDIUMJianming Antivirus IoControlCode kvcore.sys null pointer dereferenceEPSS 0.3%CVE-2023-4683MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.3%CVE-2025-1373MEDIUMFFmpeg MOV Parser mov.c mov_read_trak null pointer dereferenceEPSS 0.3%CVE-2025-13406MEDIUMScanning for higher HART revision device leads into NULL pointer dereference in live listEPSS 0.3%CVE-2026-78130HIGHstrongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.EPSS 0.3%CVE-2026-33970LOWAn issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330EPSS 0.3%CVE-2026-53463MEDIUMImageMagick: Null Pointer Dereference in distort operation when passing incorrect argumentsEPSS 0.3%CVE-2026-93588LOWImageMagick before 7.1.2-31 Null Pointer Dereference via PNMEPSS 0.3%CVE-2025-59351LOWDragonfly possibly panics due to nil pointer dereference when using variables created alongside an errorEPSS 0.3%CVE-2024-12656MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x220448 null pointer dereferenceEPSS 0.3%CVE-2023-44347MEDIUMAdobe InDesign CC 2023 Memory Corruption Vulnerability IX.EPSS 0.3%CVE-2026-12329MEDIUMMemory safety bug fixed in Thunderbird ESR 140.12EPSS 0.3%CVE-2023-44341MEDIUMAdobe InDesign CC 2023 Memory Corruption Vulnerability IEPSS 0.3%