Falhas do tipo CWE-476

2.335 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2025-46711MEDIUMGPU DDK - NULL Pointer dereference occurs in LockHandle on bridge entry when connection misusedEPSS 0.1%CVE-2026-44638LOWlibsixel: NULL pointer dereferenceEPSS 0.1%CVE-2024-53024HIGHNULL Pointer Dereference in DisplayEPSS 0.1%CVE-2026-15171MEDIUMNULL Pointer Dereference in WiresharkEPSS 0.1%CVE-2026-24918MEDIUMAddress read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-26690LOWcommunication dsoftbus has a NULL pointer vulnerabilityEPSS 0.1%CVE-2026-43864LOWmutt before 2.3.2 has a show_sig_summary NULL pointer dereference.EPSS 0.1%CVE-2026-25110LOWSensors_medical_sensor has a NULL pointer dereference vulnerabilityEPSS 0.1%CVE-2025-9548MEDIUMA potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticatedEPSS 0.1%CVE-2024-0035HIGHIn onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null checkEPSS 0.1%CVE-2021-25462LOWNULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.EPSS 0.1%CVE-2026-10199MEDIUMAssimp glTF2Asset.h LazyDict null pointer dereferenceEPSS 0.1%CVE-2021-25458LOWNULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.EPSS 0.1%CVE-2025-61143MEDIUMlibtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.EPSS 0.1%CVE-2026-1288MEDIUMRFA File Parsing Vulnerability in Autodesk RevitEPSS 0.1%CVE-2026-10197MEDIUMAssimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereferenceEPSS 0.1%CVE-2026-10198MEDIUMAssimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereferenceEPSS 0.1%CVE-2026-10298MEDIUMggml-org whisper.cpp ggml.c whisper_model_load null pointer dereferenceEPSS 0.1%CVE-2025-7018MEDIUMAvira antivirus engine null pointer dereference when scanning a malformed PE fileEPSS 0.1%CVE-2023-43541HIGHNULL Pointer Dereference in Windows GraphicsEPSS 0.1%