Falhas do tipo CWE-476

2.331 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2025-20790MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connecEPSS 0.4%CVE-2026-32696LOWNanoMQ HTTP Auth: Missing username/password can trigger a NULL-pointer strlen() in auth_http.c:set_data(), causing a process crash — SIGSEGV, remotely triggerableEPSS 0.4%CVE-2025-30671MEDIUMZoom Workplace Apps for Windows - Null PointerEPSS 0.4%CVE-2026-47143MEDIUMCapstone has a NULL Pointer Dereference with 3DNow! opcodesEPSS 0.4%CVE-2026-40195HIGHIncus nil-pointer dereference in storage bucket import allows denial of serviceEPSS 0.4%CVE-2026-8783MEDIUMomec-project amf dispatcher.go UERadioCapabilityCheckResponse null pointer dereferenceEPSS 0.4%CVE-2026-33282HIGHElla Core panics on malformed NGAP Location ReportEPSS 0.4%CVE-2021-4158A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crEPSS 0.4%CVE-2022-48606Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may afEPSS 0.4%CVE-2023-25674HIGHTensorFlow has Null Pointer Error in RandomShuffle with XLA enableEPSS 0.4%CVE-2023-25676HIGHTensorFlow has null dereference on ParallelConcat with XLAEPSS 0.4%CVE-2026-41647MEDIUMIncus: Nil-Pointer Dereference via S3 Bucket ImportEPSS 0.4%CVE-2023-25660HIGHTensorFlow vulnerable to seg fault in `tf.raw_ops.Print`EPSS 0.4%CVE-2023-25663HIGHTensorFlow has Null Pointer Error in TensorArrayConcatV2EPSS 0.4%CVE-2023-25670HIGHTensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantizeEPSS 0.4%CVE-2023-24910HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2018-14646MEDIUMThe Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the EPSS 0.4%CVE-2025-32398HIGHA NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the libraryEPSS 0.4%CVE-2026-71920MEDIUMDrayTek VigorSwitch Multiple Models NULL Pointer Dereference via formlogoutEPSS 0.4%CVE-2026-75125MEDIUMPLANET GS-4210-16P2S V3 Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_postEPSS 0.4%