Falhas do tipo CWE-476

2.331 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2026-52865HIGHNGINX Ingress Controller vulnerabilityEPSS 0.5%CVE-2026-27141HIGHSending certain HTTP/2 frames can cause a server to panic in golang.org/x/netEPSS 0.5%CVE-2023-32970MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2025-57156HIGHNULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer EPSS 0.5%CVE-2026-13084HIGHNull Pointer Dereference in WatchGuard Fireware OS iked ProcessEPSS 0.5%CVE-2022-2923MEDIUMNULL Pointer Dereference in vim/vimEPSS 0.5%CVE-2022-0617A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter funEPSS 0.5%CVE-2026-13065HIGHMongoDB $linearFill Window Function Improper Input Validation Leading to Process TerminationEPSS 0.5%CVE-2022-49201CRITICALibmvnic: fix race between xmit and resetEPSS 0.5%CVE-2024-36982HIGHDenial of Service through null pointer reference in “cluster/config” REST endpointEPSS 0.5%CVE-2025-45331HIGHbrplot v420.69.1 contains a Null Pointer Dereference (NPD) vulnerability in the br_dagens_handle_once function of its data processing moduleEPSS 0.5%CVE-2025-47210MEDIUMQsync CentralEPSS 0.5%CVE-2024-45969HIGHNULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicEPSS 0.5%CVE-2026-3408MEDIUMOpen Babel CDXML File atom.cpp GetExplicitValence null pointer dereferenceEPSS 0.5%CVE-2025-62814HIGHAn issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference of ft_handle in loadEPSS 0.5%CVE-2023-38676MEDIUMSegfault in paddle.dotEPSS 0.5%CVE-2026-46334HIGHOpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloningEPSS 0.5%CVE-2026-48139HIGHNULL pointer dereference vulnerability in NI grpc-device data moniker serviceEPSS 0.5%CVE-2023-52303MEDIUMSegfault in paddle.put_along_axisEPSS 0.5%CVE-2026-36912HIGHA NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers toEPSS 0.5%