Weaknesses of type CWE-451

345 results

Representação enganosa de informação crítica na interface

A aplicação apresenta informações de segurança ou críticas de forma enganosa, confusa ou oculta na interface. Um usuário não consegue identificar claramente riscos, avisos de segurança ou status autêntico da aplicação, levando a decisões incorretas. Exemplos comuns: cadeado falso em phishing, avisos de segurança com estilo igual a anúncios legítimos, ou status de autenticação não evidente.

Example

Um site de phishing usa CSS para desenhar um ícone de cadeado genuíno na barra de endereço, ou oculta avisos críticos de certificado inválido em texto pequeno e cor opaca. Outro caso: app mobile que não deixa claro quando uma conexão está criptografada versus em texto plano.

How to mitigate

Garanta que informações críticas (status de autenticação, certificados válidos, avisos de segurança) sejam apresentadas de forma proeminente, inambígua e não-adulterável pela aplicação. Use padrões do SO para indicadores de segurança, testes de usabilidade para validar clareza de avisos, e desconfie de interfaces que ocultam ou disfarçam estado de segurança.

CVE-2024-38112HIGHWindows MSHTML Platform Spoofing VulnerabilityEPSS 84.2%KEVCVE-2025-9491MEDIUMMicrosoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityEPSS 68.9%CVE-2024-43461HIGHWindows MSHTML Platform Spoofing VulnerabilityEPSS 51.9%KEVCVE-2024-38197MEDIUMMicrosoft Teams for iOS Spoofing VulnerabilityEPSS 16.1%CVE-2024-49040HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 7.7%CVE-2026-0907CRITICALIncorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HEPSS 7.7%CVE-2026-21527MEDIUMMicrosoft Exchange Server Spoofing VulnerabilityEPSS 7.7%CVE-2022-32816MEDIUMThe issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 1EPSS 6.7%CVE-2016-9467Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The locatiEPSS 3.0%CVE-2024-55889MEDIUMphpMyFAQ Vulnerable to Unintended File Download Triggered by Embedded FramesEPSS 2.2%CVE-2016-9468Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exceptioEPSS 2.1%CVE-2016-9473Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trEPSS 1.9%CVE-2020-10775An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbEPSS 1.8%CVE-2022-23646MEDIUMImproper CSP in Image Optimization API for Next.jsEPSS 1.8%CVE-2016-9460Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location barEPSS 1.7%CVE-2017-0888Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayedEPSS 1.5%CVE-2025-21314MEDIUMWindows SmartScreen Spoofing VulnerabilityEPSS 1.4%CVE-2025-21253MEDIUMMicrosoft Edge for IOS and Android Spoofing VulnerabilityEPSS 1.2%CVE-2021-41598UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to userEPSS 1.2%CVE-2025-21259MEDIUMMicrosoft Outlook Spoofing VulnerabilityEPSS 1.1%