Falhas do tipo CWE-476

2.335 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2026-84396MEDIUMInDesign Desktop | NULL Pointer Dereference (CWE-476)EPSS 0.1%CVE-2024-5198LOWOpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driveEPSS 0.1%CVE-2025-15535MEDIUMnicbarker clay clay.h Clay__MeasureTextCached null pointer dereferenceEPSS 0.1%CVE-2025-21998MEDIUMfirmware: qcom: uefisecapp: fix efivars registration raceEPSS 0.1%CVE-2026-76881MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2023-53401MEDIUMmm: kmem: fix a NULL pointer dereference in obj_stock_flush_required()EPSS 0.1%CVE-2025-14841MEDIUMOFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereferenceEPSS 0.1%CVE-2024-9484MEDIUMAn null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformEPSS 0.1%CVE-2026-47335MEDIUMNULL pointer dereference in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2025-39906HIGHdrm/amd/display: remove oem i2c adapter on finishEPSS 0.1%CVE-2024-9483MEDIUMUninitialized variable in digital signiture verification may crash the applicationEPSS 0.1%CVE-2026-19411LOWShim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns nullEPSS 0.1%CVE-2025-9337MEDIUMA null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, whiEPSS 0.1%CVE-2026-10659MEDIUMNULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resumeEPSS 0.1%CVE-2026-13070MEDIUMImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process TerminationEPSS 0.1%CVE-2025-8090MEDIUMVulnerability in the QNX Neutrino Kernel impacts the QNX Software Development Platform and QNX OS for SafetyEPSS 0.1%CVE-2025-60495MEDIUMA segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box before 26.02.0 allows atEPSS 0.1%CVE-2024-32666MEDIUMNULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denialEPSS 0.1%CVE-2026-9759MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2025-33237MEDIUMNVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference issue. A successful eEPSS 0.1%