Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2023-23000MEDIUMIn the Linux kernel before 5.17, drivers/phy/tegra/xusb.c mishandles the tegra_xusb_find_port_node return value. Callers expect NULL in the EPSS 0.3%CVE-2023-48363HIGHA vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMEPSS 0.3%CVE-2023-48364HIGHA vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMEPSS 0.3%CVE-2025-57611MEDIUMAn issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the dump() method allows an attEPSS 0.3%CVE-2022-49459MEDIUMthermal/drivers/broadcom: Fix potential NULL dereference in sr_thermal_probeEPSS 0.3%CVE-2025-15504MEDIUMlief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereferenceEPSS 0.3%CVE-2022-49232MEDIUMdrm/amd/display: Fix a NULL pointer dereference in amdgpu_dm_connector_add_common_modes()EPSS 0.3%CVE-2022-49498MEDIUMALSA: pcm: Check for null pointer of pointer substream before dereferencing itEPSS 0.3%CVE-2022-0168—A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet FileEPSS 0.3%CVE-2022-49187MEDIUMclk: Fix clk_hw_get_clk() when dev is NULLEPSS 0.3%CVE-2022-49449MEDIUMpinctrl: renesas: rzn1: Fix possible null-ptr-deref in sh_pfc_map_resources()EPSS 0.3%CVE-2026-76650MEDIUMPre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query Processing in TP-Link TL-WR841NEPSS 0.3%CVE-2026-76649MEDIUMPre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Processing in TP-Link TL-WR841NEPSS 0.3%CVE-2023-23005MEDIUMIn the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case,EPSS 0.3%CVE-2022-49060MEDIUMnet/smc: Fix NULL pointer dereference in smc_pnet_find_ib()EPSS 0.3%CVE-2022-49494MEDIUMmtd: rawnand: cadence: fix possible null-ptr-deref in cadence_nand_dt_probe()EPSS 0.3%CVE-2022-49376MEDIUMscsi: sd: Fix potential NULL pointer dereferenceEPSS 0.3%CVE-2022-49302MEDIUMUSB: host: isp116x: check return value after calling platform_get_resource()EPSS 0.3%CVE-2022-49375MEDIUMrtc: mt6397: check return value after calling platform_get_resource()EPSS 0.3%CVE-2022-49485MEDIUMdrm/v3d: Fix null pointer dereference of pointer perfmonEPSS 0.3%