Falhas do tipo CWE-476

2.332 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2023-47466LOWTagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is tEPSS 0.3%CVE-2022-1852—A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn inEPSS 0.3%CVE-2024-45238HIGHAn issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync oEPSS 0.3%CVE-2024-55511HIGHA null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system crash or potentiallyEPSS 0.3%CVE-2025-64085MEDIUMA NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows attackers to cause a DeEPSS 0.3%CVE-2025-64086MEDIUMA NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to causEPSS 0.3%CVE-2025-65408MEDIUMA NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allEPSS 0.3%CVE-2023-47076MEDIUMAdobe InDesign CC 2023 Memory Corruption Vulnerability IV.EPSS 0.3%CVE-2020-27830—A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checkEPSS 0.3%CVE-2023-43898MEDIUMNothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attaEPSS 0.3%CVE-2026-10593MEDIUMRemotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handlingEPSS 0.3%CVE-2023-6397MEDIUM A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX serieEPSS 0.3%CVE-2021-0111MEDIUMNULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of priEPSS 0.3%CVE-2024-0841MEDIUMKernel: hugetlbfs: null pointer dereference in hugetlbfs_fill_super functionEPSS 0.3%CVE-2025-22063MEDIUMnetlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 socketsEPSS 0.3%CVE-2022-49568MEDIUMKVM: Don't null dereference ops->destroyEPSS 0.3%CVE-2025-39851HIGHvxlan: Fix NPD when refreshing an FDB entry with a nexthop objectEPSS 0.3%CVE-2026-24813HIGHA null pointer dereference in abcz316/SKRoot-linuxKernelRootEPSS 0.3%CVE-2026-24826CRITICALOut-of-bounds write in turso3dEPSS 0.3%CVE-2025-27185MEDIUMAfter Effects | NULL Pointer Dereference (CWE-476)EPSS 0.3%