Falhas do tipo CWE-476

2.324 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2024-1914MEDIUMAn attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vEPSS 0.7%CVE-2026-1682MEDIUMFree5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereferenceEPSS 0.7%CVE-2025-14180HIGHNULL Pointer Dereference in PDO quotingEPSS 0.7%CVE-2024-36831MEDIUMA NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attacEPSS 0.7%CVE-2022-1649HIGHNull pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in radareorg/radare2EPSS 0.7%CVE-2022-36013MEDIUMNull-dereference in `mlir::tfg::GraphDefImporter::ConvertNodeDef` in TensorFlowEPSS 0.7%CVE-2022-1382MEDIUMNULL Pointer Dereference in radareorg/radare2EPSS 0.7%CVE-2022-27497HIGHNull pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allEPSS 0.7%CVE-2022-4843MEDIUMNULL Pointer Dereference in radareorg/radare2EPSS 0.7%CVE-2024-53217HIGHNFSD: Prevent NULL dereference in nfsd4_process_cb_update()EPSS 0.7%CVE-2024-34088HIGHIn FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In caseEPSS 0.7%CVE-2024-23327HIGHCrash in proxy protocol when command type of LOCAL in EnvoyEPSS 0.7%CVE-2022-49664HIGHtipc: move bc link creation back to tipc_node_createEPSS 0.7%CVE-2026-0731MEDIUMTOTOLINK WA1200 HTTP Request cstecgi.cgi null pointer dereferenceEPSS 0.7%CVE-2024-34508MEDIUMdcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.EPSS 0.7%CVE-2026-53719MEDIUMEnvoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorizationEPSS 0.7%CVE-2024-25197MEDIUMOpen Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCuEPSS 0.7%CVE-2023-46049MEDIUMLLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a crafted .o file)EPSS 0.7%CVE-2021-33572LOWDenial-of-Service (DoS) VulnerabilityEPSS 0.7%CVE-2024-43357HIGHJavaScript specification issue may lead to type confusion and pointer dereference in implementationsEPSS 0.7%