Falhas do tipo CWE-476

2.324 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2024-12660MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E018 null pointer dereferenceEPSS 0.5%CVE-2024-12658MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E01C null pointer dereferenceEPSS 0.5%CVE-2025-29889MEDIUMFile Station 5EPSS 0.5%CVE-2025-29875HIGHFile Station 5EPSS 0.5%CVE-2025-45331HIGHbrplot v420.69.1 contains a Null Pointer Dereference (NPD) vulnerability in the br_dagens_handle_once function of its data processing moduleEPSS 0.5%CVE-2026-25168MEDIUMWindows Graphics Component Denial of Service VulnerabilityEPSS 0.5%CVE-2025-29879MEDIUMFile Station 5EPSS 0.5%CVE-2025-29882MEDIUMQTS, QuTS heroEPSS 0.5%CVE-2025-29888MEDIUMFile Station 5EPSS 0.5%CVE-2025-30262MEDIUMQsync CentralEPSS 0.5%CVE-2024-12655MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x220420 null pointer dereferenceEPSS 0.5%CVE-2025-14953LOWOpen5GS FAR-ID handler.c ogs_pfcp_handle_create_pdr null pointer dereferenceEPSS 0.5%CVE-2026-9716HIGHCWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuEPSS 0.5%CVE-2025-29886MEDIUMFile Station 5EPSS 0.5%CVE-2025-30263MEDIUMQsync CentralEPSS 0.5%CVE-2026-50032HIGHNULL Pointer Dereference in MZ Automation libIEC61850EPSS 0.5%CVE-2025-29874MEDIUMFile Station 5EPSS 0.5%CVE-2025-29878MEDIUMFile Station 5EPSS 0.5%CVE-2024-12659MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E004 null pointer dereferenceEPSS 0.5%CVE-2023-50432MEDIUMsimple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service (daemon crash) by sending a DHCP packet without any EPSS 0.5%