Falhas do tipo CWE-476

2.328 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2026-8619HIGHUnauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR150, TL-MR6400 and Archer MR600EPSS 0.4%CVE-2026-0968LOWLibssh: libssh: denial of service due to malformed sftp messageEPSS 0.4%CVE-2026-22693MEDIUMNull Pointer Dereference in SubtableUnicodesCache::create leading to DoSEPSS 0.4%CVE-2026-30072HIGHA NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crEPSS 0.4%CVE-2022-4285MEDIUMAn illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may resulEPSS 0.4%CVE-2024-54130CRITICALSegmentation Fault in `forwardBundle` Function of ION-DTN BPv7 When Destination EID is `dtn:none` (public)EPSS 0.4%CVE-2024-41164HIGHBIG-IP MPTCP vulnerabilityEPSS 0.4%CVE-2026-17510HIGHCrypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attributeEPSS 0.4%CVE-2025-65563HIGHA denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.EPSS 0.4%CVE-2025-21676HIGHnet: fec: handle page_pool_dev_alloc_pages errorEPSS 0.4%CVE-2024-11148HIGHOpenBSD httpd(8) null dereferenceEPSS 0.4%CVE-2026-45541HIGHESF-IDF: Remote Null Pointer Dereference in WebSocket ServerEPSS 0.4%CVE-2023-40546MEDIUMShim: out-of-bounds read printing error messagesEPSS 0.4%CVE-2022-1263A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged loEPSS 0.4%CVE-2026-15690LOWopen62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereferenceEPSS 0.4%CVE-2023-41274MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.4%CVE-2025-53141HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-53154HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-61668HIGH@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous userEPSS 0.4%CVE-2026-23831MEDIUMRekor COSE v0.0.1 Canonicalize crashes when passed empty MessageEPSS 0.4%