Falhas do tipo CWE-476

2.335 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2023-53245MEDIUMscsi: storvsc: Fix handling of virtual Fibre Channel timeoutsEPSS 0.1%CVE-2023-53250MEDIUMfirmware: dmi-sysfs: Fix null-ptr-deref in dmi_sysfs_register_handleEPSS 0.1%CVE-2026-76922MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2025-6966MEDIUMNull-pointer dereference in python-apt TagSection.keys()EPSS 0.1%CVE-2023-53294MEDIUMfs/ntfs3: Fix null-ptr-deref on inode->i_op in ntfs_lookup()EPSS 0.1%CVE-2023-53302MEDIUMwifi: iwl4965: Add missing check for create_singlethread_workqueue()EPSS 0.1%CVE-2023-53251MEDIUMwifi: iwlwifi: pcie: fix NULL pointer dereference in iwl_pcie_irq_rx_msix_handler()EPSS 0.1%CVE-2023-53389MEDIUMdrm/mediatek: dp: Only trigger DRM HPD events if bridge is attachedEPSS 0.1%CVE-2023-53328MEDIUMfs/ntfs3: Enhance sanity check while generating attr_listEPSS 0.1%CVE-2023-53326MEDIUMpowerpc: Don't try to copy PPR for task with NULL pt_regsEPSS 0.1%CVE-2026-21350MEDIUMAfter Effects | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2026-21336MEDIUMSubstance3D - Designer | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2025-39850MEDIUMvxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objectsEPSS 0.1%CVE-2025-60481MEDIUMA NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackersEPSS 0.1%CVE-2025-13397MEDIUMmrubyc alloc.c mrbc_raw_realloc null pointer dereferenceEPSS 0.1%CVE-2023-53332MEDIUMgenirq/ipi: Fix NULL pointer deref in irq_data_get_affinity_mask()EPSS 0.1%CVE-2026-65367MEDIUMA null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iEPSS 0.1%CVE-2023-53260MEDIUMovl: fix null pointer dereference in ovl_permission()EPSS 0.1%CVE-2025-24031MEDIUMPAM-PKCS#11 vulnerable to segmentation fault on ctrl-c/ctrl-d when asked for PINEPSS 0.1%CVE-2023-53248MEDIUMdrm/amdgpu: install stub fence into potential unused fence pointersEPSS 0.1%