Falhas do tipo CWE-476

2.335 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2026-82926MEDIUMNULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aEPSS 0.1%CVE-2026-3776MEDIUMNull pointer dereference in Foxit PDF Editor/Reader when accessing stamp annotationEPSS 0.1%CVE-2026-17574MEDIUMNULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type TagEPSS 0.1%CVE-2025-20675MEDIUMIn wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execEPSS 0.1%CVE-2026-42442LOWNanaZip: Null-pointer dereference in NanaZip UFS parser when root inode is a symlinkEPSS 0.1%CVE-2025-20676MEDIUMIn wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execEPSS 0.1%CVE-2025-10823MEDIUMaxboe fio options.c str_buffer_pattern_cb null pointer dereferenceEPSS 0.1%CVE-2025-23300MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocaEPSS 0.1%CVE-2025-60007MEDIUMJunos OS: A specifically crafted 'show chassis' command causes chassisd to crashEPSS 0.1%CVE-2026-24805MEDIUMMishandles certain out-of-memory conditions in visualfc/liteide via liteidex/src/3rdparty/libvterm/src moduleEPSS 0.1%CVE-2025-45525LOWA NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a lightweight syntax highliEPSS 0.1%CVE-2023-53292MEDIUMblk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_noneEPSS 0.1%CVE-2025-39895MEDIUMsched: Fix sched_numa_find_nth_cpu() if mask offlineEPSS 0.1%CVE-2026-6845MEDIUMBinutils: binutils: denial of service via crafted elf fileEPSS 0.1%CVE-2023-53380MEDIUMmd/raid10: fix null-ptr-deref of mreplace in raid10_sync_requestEPSS 0.1%CVE-2025-62815MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.astEPSS 0.1%CVE-2026-21338MEDIUMSubstance3D - Designer | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2023-53296MEDIUMsctp: check send stream number after wait_for_sndbufEPSS 0.1%CVE-2026-21350MEDIUMAfter Effects | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2023-53245MEDIUMscsi: storvsc: Fix handling of virtual Fibre Channel timeoutsEPSS 0.1%