Falhas do tipo CWE-476

2.335 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2025-7007HIGHNull pointer dereference in Avast Antivirus on macOS (16.0.0) or Linux (3.0.3)EPSS 0.1%CVE-2025-13425LOWDenial of Service in OSV-SCALIBREPSS 0.1%CVE-2025-46592MEDIUMNull pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availabEPSS 0.1%CVE-2025-60477MEDIUMA NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before EPSS 0.1%CVE-2024-56188MEDIUMthere is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with no additional execuEPSS 0.1%CVE-2024-47290MEDIUMInput validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2023-33036HIGHNULL Pointer Dereference in HypervisorEPSS 0.1%CVE-2021-25491LOWA vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.EPSS 0.1%CVE-2026-20771MEDIUMNull pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow aEPSS 0.1%CVE-2025-27701MEDIUMIn the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_arraEPSS 0.1%CVE-2026-20914MEDIUMNull pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow EPSS 0.1%CVE-2026-20064MEDIUMA vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause the device tEPSS 0.1%CVE-2024-23357MEDIUMNULL Pointer Dereference in HLOSEPSS 0.1%CVE-2025-53170MEDIUMNull pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vulnerability may affectEPSS 0.1%CVE-2022-48231MEDIUMIn soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privEPSS 0.1%CVE-2022-48241MEDIUMIn telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution EPSS 0.1%CVE-2022-44447MEDIUMIn wlan driver, there is a possible null pointer dereference issue due to a missing bounds check. This could lead to local denial of serviceEPSS 0.1%CVE-2024-29751MEDIUMIn asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information EPSS 0.1%CVE-2026-17009MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2024-27232MEDIUMIn asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclEPSS 0.1%