Falhas do tipo CWE-476

2.332 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2025-45333HIGHberkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing moduEPSS 0.4%CVE-2025-62609MEDIUMMLX has Wild Pointer Dereference in load_gguf()EPSS 0.4%CVE-2024-12653MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x22040C null pointer dereferenceEPSS 0.4%CVE-2025-8033MEDIUMIncorrect JavaScript state machine for generatorsEPSS 0.4%CVE-2024-12657MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E000 null pointer dereferenceEPSS 0.4%CVE-2026-8252MEDIUMOpen5GS SMF smf_nsmf_handle_create_data_in_hsmf null pointer dereferenceEPSS 0.4%CVE-2025-65493HIGHNULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLSEPSS 0.4%CVE-2024-37820MEDIUMA nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation.EPSS 0.4%CVE-2024-39132MEDIUMA NULL Pointer Dereference vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function VerifyCommaEPSS 0.4%CVE-2026-42183LOWArgo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)EPSS 0.4%CVE-2025-63648HIGHA NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackerEPSS 0.4%CVE-2022-2476—A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL =====================EPSS 0.4%CVE-2023-3012MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.4%CVE-2019-16230MEDIUMdrivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointeEPSS 0.4%CVE-2025-49694HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-29838HIGHWindows ExecutionContext Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-42902MEDIUMMemory Corruption vulnerability in SAP Netweaver AS ABAP and ABAP PlatformEPSS 0.4%CVE-2025-29901HIGHFile Station 5EPSS 0.4%CVE-2025-30267MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2025-30275MEDIUMQsync CentralEPSS 0.4%