Falhas do tipo CWE-476

2.331 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2025-20045HIGHBIG-IP SIP MRF VulnerabilityEPSS 0.4%CVE-2025-48722LOWQsync CentralEPSS 0.4%CVE-2025-70116MEDIUMA NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing desEPSS 0.4%CVE-2025-54147LOWQsync CentralEPSS 0.4%CVE-2025-47209LOWQsync CentralEPSS 0.4%CVE-2026-31256HIGHA null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the procesEPSS 0.4%CVE-2025-30266LOWQsync CentralEPSS 0.4%CVE-2025-52984HIGHJunos OS and Junos OS Evolved: When a static route points to a reject next-hop and a gNMI query for this route is processed, RPD crashesEPSS 0.4%CVE-2022-25733HIGHNull Pointer Dereference in MODEMEPSS 0.4%CVE-2022-25735HIGHNull Pointer Dereference in MODEMEPSS 0.4%CVE-2023-42754MEDIUMKernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()EPSS 0.4%CVE-2026-82803MEDIUMarmink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMENT null pointer dereferenceEPSS 0.4%CVE-2026-44316HIGHfree5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereferenceEPSS 0.4%CVE-2023-37028MEDIUMA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95EPSS 0.4%CVE-2025-7462MEDIUMArtifex GhostPDL New Output File Open Error gdevpdf.c pdf_ferror null pointer dereferenceEPSS 0.4%CVE-2025-50635HIGHA null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function ofEPSS 0.4%CVE-2025-62466HIGHWindows Client-Side Caching Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-57719MEDIUMlunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.EPSS 0.4%CVE-2026-32134MEDIUMNanoMQ: NULL Pointer Dereference Crash in tcptran_pipe_peer During Session RestoreEPSS 0.4%CVE-2026-40413HIGHWindows TCP/IP Denial of Service VulnerabilityEPSS 0.4%