Falhas do tipo CWE-476

2.335 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2026-32849MEDIUMNetBSD Signed Integer Overflow in cryptodev_op via cryptodev.cEPSS 0.2%CVE-2024-6157MEDIUMAn attacker who successfully exploited these vulnerabilities could cause the robot to stop. A vulnerability exists in the PROFINET stack EPSS 0.2%CVE-2022-41593LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2026-10670MEDIUMUser-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifierEPSS 0.2%CVE-2022-41598LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41595LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41592LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41594LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41603LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2025-6398MEDIUMA null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a speciaEPSS 0.1%CVE-2025-63745MEDIUMA NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binarEPSS 0.1%CVE-2024-0086MEDIUMCVEEPSS 0.1%CVE-2024-58073MEDIUMdrm/msm/dpu: check dpu_plane_atomic_print_state() for valid ssppEPSS 0.1%CVE-2024-58066MEDIUMclk: mmp: pxa1908-apbcp: Fix a NULL vs IS_ERR() checkEPSS 0.1%CVE-2024-58065MEDIUMclk: mmp: pxa1908-apbc: Fix NULL vs IS_ERR() checkEPSS 0.1%CVE-2023-53289MEDIUMmedia: bdisp: Add missing check for create_workqueueEPSS 0.1%CVE-2023-53384MEDIUMwifi: mwifiex: avoid possible NULL skb pointer dereferenceEPSS 0.1%CVE-2025-8735MEDIUMGNU cflow Lexer c.c yylex null pointer dereferenceEPSS 0.1%CVE-2023-53440HIGHnilfs2: fix sysfs interface lifetimeEPSS 0.1%CVE-2024-58067MEDIUMclk: mmp: pxa1908-mpmu: Fix a NULL vs IS_ERR() checkEPSS 0.1%