Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2023-24755MEDIUMlibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. ThEPSS 0.3%CVE-2023-24758MEDIUMlibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. EPSS 0.3%CVE-2025-27185MEDIUMAfter Effects | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2023-3106MEDIUMKernel: netlink socket crash (null pointer deref) in netlink_dump functionEPSS 0.3%CVE-2023-24757MEDIUMlibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc.EPSS 0.3%CVE-2023-24756MEDIUMlibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. ThEPSS 0.3%CVE-2022-49492MEDIUMnvme-pci: fix a NULL pointer dereference in nvme_alloc_admin_tagsEPSS 0.3%CVE-2022-49307MEDIUMtty: synclink_gt: Fix null-pointer-dereference in slgt_clean()EPSS 0.3%CVE-2022-49450MEDIUMrxrpc: Fix listen() setting the bar too high for the prealloc ringsEPSS 0.3%CVE-2023-46048MEDIUMTex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized aEPSS 0.3%CVE-2025-63744MEDIUMA NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. ProcessiEPSS 0.3%CVE-2024-55069MEDIUMffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c.EPSS 0.3%CVE-2026-2507HIGHBIG-IP TMM VulnerabilityEPSS 0.3%CVE-2025-24179MEDIUMA null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macEPSS 0.3%CVE-2023-53382CRITICALnet/smc: Reset connection when trying to use SMCRv2 fails.EPSS 0.3%CVE-2023-3355MEDIUMNull pointer dereference in submit_lookup_cmds() in drivers/gpu/drm/msm/msm_gem_submit.cEPSS 0.3%CVE-2026-42800HIGHDeference after null check in ims_client sipEPSS 0.3%CVE-2024-28577MEDIUMNull Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) EPSS 0.3%CVE-2025-62817HIGHAn issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of sessiEPSS 0.3%CVE-2026-20457MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connecEPSS 0.3%