Falhas do tipo CWE-476

2.328 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2023-24938MEDIUMWindows CryptoAPI Denial of Service VulnerabilityEPSS 2.0%CVE-2019-12654HIGHCisco IOS and IOS XE Software Session Initiation Protocol Denial of Service VulnerabilityEPSS 2.0%CVE-2019-12647HIGHCisco IOS and IOS XE Software IP Ident Denial of Service VulnerabilityEPSS 2.0%CVE-2023-21683HIGHWindows Internet Key Exchange (IKE) Extension Denial of Service VulnerabilityEPSS 2.0%CVE-2021-42528MEDIUMXMP-Toolkit Null Pointer Dereference Application denial-of-serviceEPSS 2.0%CVE-2023-35338HIGHWindows Peer Name Resolution Protocol Denial of Service VulnerabilityEPSS 2.0%CVE-2021-41689HIGHDCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and EPSS 2.0%CVE-2023-2953HIGHA vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.EPSS 1.9%CVE-2021-39852MEDIUMAdobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceEPSS 1.9%CVE-2021-39851MEDIUMAdobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceEPSS 1.9%CVE-2021-39850MEDIUMAdobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceEPSS 1.9%CVE-2021-39849MEDIUMAdobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceEPSS 1.9%CVE-2021-20274A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.EPSS 1.9%CVE-2021-35985MEDIUMAdobe Acrobat Pro DC PDFLibTool Null Pointer Dereference BugEPSS 1.9%CVE-2019-1900HIGHCisco Integrated Management Controller Unauthenticated Denial of Service VulnerabilityEPSS 1.9%CVE-2021-3596A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is dueEPSS 1.9%CVE-2020-13583HIGHA denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lEPSS 1.9%CVE-2025-0492HIGHD-Link DIR-823X FUN_00412244 null pointer dereferenceEPSS 1.9%CVE-2021-28601LOWAdobe After Effects NULL Pointer Dereference vulnerabilityEPSS 1.9%CVE-2025-11848MEDIUMA null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 EPSS 1.8%