Falhas do tipo CWE-476

2.332 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2025-65566HIGHA denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF EPSS 0.3%CVE-2023-33109HIGHNULL Pointer Dereference in WLAN FirmwareEPSS 0.3%CVE-2026-93312MEDIUMFreedesktop Poppler JBIG2Stream.cc rewind null pointer dereferenceEPSS 0.3%CVE-2026-52878HIGHKlever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the chainEPSS 0.3%CVE-2026-15891HIGHNULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gatewayEPSS 0.3%CVE-2025-47111MEDIUMAcrobat Reader | NULL Pointer Dereference (CWE-476)EPSS 0.3%CVE-2022-29201MEDIUMMissing validation in `QuantizedConv2D` results in undefined behavior in TensorFlowEPSS 0.3%CVE-2025-52585HIGHBIG-IP Client SSL profile vulnerabilityEPSS 0.3%CVE-2024-10037MEDIUMA vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crEPSS 0.3%CVE-2022-48509—Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulEPSS 0.3%CVE-2026-50315HIGHWindows Image Acquisition Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-53592LOWQTS, QuTS heroEPSS 0.3%CVE-2022-34683MEDIUMNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a nuEPSS 0.3%CVE-2025-44013LOWQTS, QuTS heroEPSS 0.3%CVE-2025-54326HIGHAn issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in theEPSS 0.3%CVE-2025-62850MEDIUMQuTS heroEPSS 0.3%CVE-2025-54332HIGHAn issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Dereference of profiler.noEPSS 0.3%CVE-2025-54334HIGHAn issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL PointEPSS 0.3%CVE-2026-40401HIGHWindows TCP/IP Denial of Service VulnerabilityEPSS 0.3%CVE-2026-24716LOWQTS, QuTS heroEPSS 0.3%