Fallos del tipo CWE-476

2332 resultados

Desreferência de ponteiro nulo autenticada remota

A aplicação tenta acessar um objeto ou endereço de memória que não foi inicializado ou foi definido como nulo, sem verificar essa condição antes. Um atacante autenticado consegue provocar esse acesso inválido enviando dados malformados ou inesperados, causando crash ou comportamento indefinido.

Ejemplo

Um endpoint autenticado de API recebe um ID de usuário, faz uma busca no banco que retorna nulo (usuário não existe) e tenta acessar diretamente campos desse objeto nulo sem validação — resultando em erro 500 ou travamento da aplicação.

Cómo mitigar

Sempre verificar se um objeto é nulo antes de usá-lo; usar análise estática (linters, SAST) para detectar acessos potenciais a nulos; validar e tratar casos onde dados esperados podem estar ausentes, mesmo que o usuário esteja autenticado.

CVE-2023-34323MEDIUMxenstored: A transaction conflict can crash C XenstoredEPSS 0.3%CVE-2025-69649MEDIUMGNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header EPSS 0.3%CVE-2026-3202MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.3%CVE-2024-25453MEDIUMBento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.EPSS 0.3%CVE-2022-3202—A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attaEPSS 0.3%CVE-2024-26744MEDIUMRDMA/srpt: Support specifying the srpt_service_guid parameterEPSS 0.3%CVE-2024-56634MEDIUMgpio: grgpio: Add NULL check in grgpio_probeEPSS 0.3%CVE-2024-56587MEDIUMleds: class: Protect brightness_show() with led_cdev->led_access mutexEPSS 0.3%CVE-2025-6375MEDIUMpoco MultipartReader.cpp MultipartInputStream null pointer dereferenceEPSS 0.3%CVE-2024-50296MEDIUMnet: hns3: fix kernel crash when uninstalling driverEPSS 0.3%CVE-2024-45828MEDIUMi3c: mipi-i3c-hci: Mask ring interrupts before ring stop requestEPSS 0.3%CVE-2024-50117HIGHdrm/amd: Guard against bad data for ATIF ACPI methodEPSS 0.3%CVE-2024-48881MEDIUMbcache: revert replacing IS_ERR_OR_NULL with IS_ERR againEPSS 0.3%CVE-2026-47307MEDIUMNULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a denial of service via a crafted WebAssembEPSS 0.3%CVE-2023-37026MEDIUMA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95EPSS 0.3%CVE-2025-22031MEDIUMPCI/bwctrl: Fix NULL pointer dereference on bus number exhaustionEPSS 0.3%CVE-2021-47645MEDIUMmedia: staging: media: zoran: calculate the right buffer number for zoran_reap_stat_comEPSS 0.3%CVE-2024-2496MEDIUMLibvirt: null pointer dereference in udevconnectlistallinterfaces()EPSS 0.3%CVE-2023-37035MEDIUMA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95EPSS 0.3%CVE-2024-20794MEDIUMAdobe Animate 2024 WAV File Parsing Null Pointer DereferenceEPSS 0.3%