Falhas do tipo CWE-476

2.335 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2023-53260MEDIUMovl: fix null pointer dereference in ovl_permission()EPSS 0.1%CVE-2023-53442MEDIUMice: Block switchdev mode when ADQ is active and vice versaEPSS 0.1%CVE-2025-39903MEDIUMof_numa: fix uninitialized memory nodes causing kernel panicEPSS 0.1%CVE-2023-53444MEDIUMdrm/ttm: fix bulk_move corruption when adding a entryEPSS 0.1%CVE-2025-60481MEDIUMA NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackersEPSS 0.1%CVE-2023-53284MEDIUMdrm/msm/dpu: check for null return of devm_kzalloc() in dpu_writeback_init()EPSS 0.1%CVE-2025-24515MEDIUMNULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via locaEPSS 0.1%CVE-2025-60485MEDIUMA segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before 26.02.0 allows attaEPSS 0.1%CVE-2025-13397MEDIUMmrubyc alloc.c mrbc_raw_realloc null pointer dereferenceEPSS 0.1%CVE-2025-23332MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deferEPSS 0.1%CVE-2025-25218LOWthird_party_mksh has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2025-27241LOWmultimedia_av_codec has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2026-48066MEDIUMpam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authenticationEPSS 0.1%CVE-2025-22837LOWArkcompiler Ets Runtime has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2026-8035MEDIUMNULL pointer dereference in NI-PALEPSS 0.1%CVE-2026-6526MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2025-27248LOWai_neural_network_runtime has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2025-21097LOWArkcompiler Ets Runtime has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2026-63380MEDIUMLibevent: Null Pointer Dereference in `evws_new_session`EPSS 0.1%CVE-2026-6525MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%