Falhas do tipo CWE-476

2.332 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2025-53596LOWQTS, QuTS heroEPSS 0.3%CVE-2022-41843MEDIUMAn issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-3892EPSS 0.3%CVE-2025-58120HIGHBIG-IP Next (CNF, SPK, and Kubernetes) vulnerabilityEPSS 0.3%CVE-2025-52426LOWQTS, QuTS heroEPSS 0.3%CVE-2025-52430LOWQTS, QuTS heroEPSS 0.3%CVE-2026-57873HIGHGV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEEE8021x_upload.cgi)EPSS 0.3%CVE-2025-61960HIGHBIG-IP APM portal access vulnerabilityEPSS 0.3%CVE-2025-53590LOWQTSEPSS 0.3%CVE-2025-52431LOWQTS, QuTS heroEPSS 0.3%CVE-2024-24446MEDIUMAn uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a craEPSS 0.3%CVE-2026-72582HIGHfastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery EndpointEPSS 0.3%CVE-2025-63929HIGHA null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple threads enqueue elementEPSS 0.3%CVE-2024-52296MEDIUMlibosdp has a null pointer deref in osdp_reply_nameEPSS 0.3%CVE-2024-6062MEDIUMGPAC MP4Box load_text.c swf_svg_add_iso_sample null pointer dereferenceEPSS 0.3%CVE-2026-67288HIGHFreeRDP before 3.29.0 Denial of Service via smartcard cacheEPSS 0.3%CVE-2026-91954HIGHFreeRDP before 3.31.0 NULL Pointer Dereference via NSCodecEPSS 0.3%CVE-2025-55659MEDIUMA NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial EPSS 0.3%CVE-2026-16702MEDIUMIBM® Db2® federated server could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereferenceEPSS 0.3%CVE-2025-45332HIGHvkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leadinEPSS 0.3%CVE-2026-26457HIGHccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg() function when procesEPSS 0.3%