Falhas do tipo CWE-476

2.332 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2024-12654MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x220408 null pointer dereferenceEPSS 0.3%CVE-2019-10140MEDIUMA vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a deEPSS 0.3%CVE-2022-29205MEDIUMSegfault due to missing support for quantized types in TensorFlowEPSS 0.3%CVE-2024-12662MEDIUMIObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E040 null pointer dereferenceEPSS 0.3%CVE-2026-21689MEDIUMiccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cppEPSS 0.3%CVE-2023-45925—GNU Midnight Commander 4.8.29-146-g299d9a2fb was discovered to contain a NULL pointer dereference via the function x_error_handler() at tty/EPSS 0.3%CVE-2020-35505—A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurEPSS 0.3%CVE-2023-1628MEDIUMJianming Antivirus IoControlCode kvcore.sys null pointer dereferenceEPSS 0.3%CVE-2023-4683MEDIUMNULL Pointer Dereference in gpac/gpacEPSS 0.3%CVE-2025-1373MEDIUMFFmpeg MOV Parser mov.c mov_read_trak null pointer dereferenceEPSS 0.3%CVE-2025-13406MEDIUMScanning for higher HART revision device leads into NULL pointer dereference in live listEPSS 0.3%CVE-2026-78130HIGHstrongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.EPSS 0.3%CVE-2026-33970LOWAn issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330EPSS 0.3%CVE-2026-53463MEDIUMImageMagick: Null Pointer Dereference in distort operation when passing incorrect argumentsEPSS 0.3%CVE-2026-93588LOWImageMagick before 7.1.2-31 Null Pointer Dereference via PNMEPSS 0.3%CVE-2025-59351LOWDragonfly possibly panics due to nil pointer dereference when using variables created alongside an errorEPSS 0.3%CVE-2024-12656MEDIUMFabulaTech USB over Network IOCT ftusbbus2.sys 0x220448 null pointer dereferenceEPSS 0.3%CVE-2023-44347MEDIUMAdobe InDesign CC 2023 Memory Corruption Vulnerability IX.EPSS 0.3%CVE-2026-12329MEDIUMMemory safety bug fixed in Thunderbird ESR 140.12EPSS 0.3%CVE-2023-44341MEDIUMAdobe InDesign CC 2023 Memory Corruption Vulnerability IEPSS 0.3%