Falhas do tipo CWE-476

2.331 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2022-3113MEDIUMAn issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.EPSS 0.7%CVE-2022-43495MEDIUMAn abnormal packet recieved when distributedhardware_device_manager joining a network could cause a device reboot.EPSS 0.7%CVE-2022-41787HIGHBIG-IP DNS Express vulnerability CVE-2022-41787EPSS 0.7%CVE-2024-7652HIGHType Confusion in Async Generators in Javascript EngineEPSS 0.7%CVE-2024-36626MEDIUMIn prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.EPSS 0.7%CVE-2024-11705CRITICAL`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV)EPSS 0.7%CVE-2021-39977HIGHThe HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to reEPSS 0.7%CVE-2021-39988HIGHThe HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to reEPSS 0.7%CVE-2024-38612HIGHipv6: sr: fix invalid unregister error pathEPSS 0.7%CVE-2026-28886MEDIUMA null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iEPSS 0.7%CVE-2026-33063HIGHfree5GC AUSF UE Authentication Panic on Nil SuciSupiMap Interface ConversionEPSS 0.7%CVE-2025-53603HIGHIn Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request EPSS 0.7%CVE-2023-2840MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.7%CVE-2024-23078CRITICALJGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compaEPSS 0.7%CVE-2025-31115HIGHXZ has a heap-use-after-free bug in threaded .xz decoderEPSS 0.7%CVE-2024-31755HIGHcJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuesEPSS 0.6%CVE-2023-31129HIGHContiki-NG missing NULL pointer check in IPv6 neighbor discoveryEPSS 0.6%CVE-2024-36476CRITICALRDMA/rtrs: Ensure 'ib_sge list' is accessibleEPSS 0.6%CVE-2022-49065HIGHSUNRPC: Fix the svc_deferred_event trace classEPSS 0.6%CVE-2024-27660MEDIUMD-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to caEPSS 0.6%