Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2023-47466LOWTagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is tEPSS 0.3%CVE-2022-1852—A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn inEPSS 0.3%CVE-2024-45238HIGHAn issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync oEPSS 0.3%CVE-2024-55511HIGHA null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system crash or potentiallyEPSS 0.3%CVE-2025-64085MEDIUMA NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows attackers to cause a DeEPSS 0.3%CVE-2025-64086MEDIUMA NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to causEPSS 0.3%CVE-2025-65408MEDIUMA NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allEPSS 0.3%CVE-2023-47076MEDIUMAdobe InDesign CC 2023 Memory Corruption Vulnerability IV.EPSS 0.3%CVE-2020-27830—A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checkEPSS 0.3%CVE-2023-43898MEDIUMNothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attaEPSS 0.3%CVE-2026-10593MEDIUMRemotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handlingEPSS 0.3%CVE-2023-6397MEDIUM A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX serieEPSS 0.3%CVE-2021-0111MEDIUMNULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of priEPSS 0.3%CVE-2024-0841MEDIUMKernel: hugetlbfs: null pointer dereference in hugetlbfs_fill_super functionEPSS 0.3%CVE-2025-22063MEDIUMnetlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 socketsEPSS 0.3%CVE-2022-49568MEDIUMKVM: Don't null dereference ops->destroyEPSS 0.3%CVE-2025-39851HIGHvxlan: Fix NPD when refreshing an FDB entry with a nexthop objectEPSS 0.3%CVE-2026-24813HIGHA null pointer dereference in abcz316/SKRoot-linuxKernelRootEPSS 0.3%CVE-2026-24826CRITICALOut-of-bounds write in turso3dEPSS 0.3%CVE-2025-27185MEDIUMAfter Effects | NULL Pointer Dereference (CWE-476)EPSS 0.3%