Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-20906MEDIUMProtection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an EPSS 0.2%CVE-2026-11219MEDIUMInappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictioEPSS 0.2%CVE-2026-54577LOWmport audit can inspect the wrong package when options are presentEPSS 0.2%CVE-2026-6774MEDIUMMitigation bypass in the DOM: Security componentEPSS 0.2%CVE-2025-3770HIGHSMM IDT Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-29864MEDIUMProtection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZip: from 12.01 beforeEPSS 0.1%CVE-2026-56585LOWHCL IEM was affected with the Anti Clickjacking XFrame Options Header MissingEPSS 0.1%CVE-2025-36938MEDIUMIn U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalatioEPSS 0.1%CVE-2026-7937LOWInsufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a maEPSS 0.1%CVE-2026-30904LOWProtection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of inforEPSS 0.1%CVE-2023-20919HIGHIn getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error in the code. This couEPSS 0.1%CVE-2025-43296MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.EPSS 0.1%CVE-2026-49859MEDIUMDeno: `fetch()` API sandbox bypass via missing DNS resolution checkEPSS 0.1%CVE-2024-0029HIGHIn multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. TEPSS 0.1%CVE-2026-71858MEDIUMNotepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command ExecutionEPSS 0.1%CVE-2026-84578HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app EPSS 0.1%CVE-2025-24835MEDIUMProtection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 32.0.101.6737 may allEPSS 0.1%CVE-2025-21081LOWProtection mechanism failure for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentEPSS 0.1%CVE-2024-0014HIGHIn startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead toEPSS 0.1%CVE-2025-26443HIGHIn parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to EPSS 0.1%