Weaknesses of type CWE-703

174 results

Tratamento inadequado de condições de erro

Quando o código não verifica ou trata corretamente situações anormais (erros, exceções, valores inesperados), ele pode se comportar de forma impredizível ou insegura. O programa segue um caminho que não deveria, ignorando sinais de falha que poderiam evitar consequências maiores.

Example

Um serviço lê um arquivo de configuração sem verificar se a leitura falhou; se o arquivo não existir, as variáveis ficam vazias ou com lixo de memória, e o programa usa valores inválidos em decisões críticas de segurança, abrindo brechas para ataques.

How to mitigate

Sempre capture e trate exceções explicitamente, valide retornos de função (códigos de erro, null, valores fora do escopo), e log eventos anômalos. Implemente fallbacks sensatos e recuse operações quando o estado não for confiável.

CVE-2021-0241HIGHJunos OS: Receipt of specific DHCPv6 packet may cause jdhcpd to crash and restartEPSS 0.4%CVE-2025-3084MEDIUMMongoDB Server may crash due to improper validation of explain commandEPSS 0.4%CVE-2021-0240HIGHJunos OS: Receipt of malformed DHCPv6 packets causes jdhcpd to crash and restart.EPSS 0.4%CVE-2026-61822MEDIUMpg_partman disable maintenance for all partition setsEPSS 0.4%CVE-2025-61602HIGHBigBlueButton vulnerable to Chat DoS via invalid reactionEmojiIdEPSS 0.4%CVE-2022-22265MEDIUMAn improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and codeEPSS 0.4%KEVCVE-2025-31998LOWHCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive informationEPSS 0.4%CVE-2023-0204MEDIUMNVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can cause improper hEPSS 0.4%CVE-2025-64435MEDIUMKubeVirt VMI Denial-of-Service (DoS) Using Pod ImpersonationEPSS 0.4%CVE-2026-92790MEDIUMHigress before 2.2.4 Rate Limit Bypass via Malformed Cookie HeaderEPSS 0.4%CVE-2025-11594MEDIUMywxbear PHP-Bookstore-Website-Example Quantity index.php improper validation of specified quantity in inputEPSS 0.4%CVE-2024-38482MEDIUMCloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A higEPSS 0.4%CVE-2023-39136An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafteEPSS 0.4%CVE-2025-59322HIGHCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mountedEPSS 0.4%CVE-2025-13021CRITICALIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2025-13022CRITICALIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2025-13023CRITICALSandbox escape due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2025-13026CRITICALSandbox escape due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-28407MEDIUMmalcontent's nested archive extraction failure can drop content from scan inputsEPSS 0.4%CVE-2026-26446HIGHStomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peerEPSS 0.3%