Weaknesses of type CWE-693

820 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2025-52643MEDIUMHCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environmentEPSS 0.1%CVE-2024-49720HIGHIn multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic eEPSS 0.1%CVE-2025-22433HIGHIn canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work ProfEPSS 0.1%CVE-2026-28639HIGHIn rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local esEPSS 0.1%CVE-2026-54073MEDIUMVeraCrypt: Hidden volume quick format weakens plausible deniabilityEPSS 0.1%CVE-2025-26458HIGHIn multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic error in the code. ThisEPSS 0.1%CVE-2025-26444HIGHIn onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the defaultEPSS 0.1%CVE-2025-22427HIGHIn onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due tEPSS 0.1%CVE-2025-48546HIGHIn checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This couldEPSS 0.1%CVE-2025-22434HIGHIn handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could leaEPSS 0.1%CVE-2025-22437HIGHIn setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in EPSS 0.1%CVE-2025-26431HIGHIn setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logicEPSS 0.1%CVE-2026-0189HIGHIn ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2026-56881HIGHIn enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2025-26439HIGHIn getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead ofEPSS 0.1%CVE-2025-36905HIGHIn gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local EPSS 0.1%CVE-2025-36898HIGHThere is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additEPSS 0.1%CVE-2026-0118HIGHIn oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalation of privilege withEPSS 0.1%CVE-2026-0045HIGHIn bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. TEPSS 0.1%CVE-2026-56979MEDIUMIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%