Weaknesses of type CWE-703

174 results

Tratamento inadequado de condições de erro

Quando o código não verifica ou trata corretamente situações anormais (erros, exceções, valores inesperados), ele pode se comportar de forma impredizível ou insegura. O programa segue um caminho que não deveria, ignorando sinais de falha que poderiam evitar consequências maiores.

Example

Um serviço lê um arquivo de configuração sem verificar se a leitura falhou; se o arquivo não existir, as variáveis ficam vazias ou com lixo de memória, e o programa usa valores inválidos em decisões críticas de segurança, abrindo brechas para ataques.

How to mitigate

Sempre capture e trate exceções explicitamente, valide retornos de função (códigos de erro, null, valores fora do escopo), e log eventos anômalos. Implemente fallbacks sensatos e recuse operações quando o estado não for confiável.

CVE-2021-25366LOWImproper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's autEPSS 0.3%CVE-2023-44203MEDIUMJunos OS: QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLANEPSS 0.3%CVE-2024-37995LOWA vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6EPSS 0.3%CVE-2026-47316MEDIUMImproper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issEPSS 0.3%CVE-2026-34388MEDIUMFleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpointEPSS 0.3%CVE-2026-82417MEDIUMqs.stringify throws TypeError on objects with a non-callable constructor.isBuffer propertyEPSS 0.3%CVE-2021-42205MEDIUMELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a sEPSS 0.3%CVE-2021-25348LOWImproper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorizedEPSS 0.3%CVE-2022-39911MEDIUMImproper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access SamsuEPSS 0.3%CVE-2026-57445HIGHGardens v2: Approve-side dispute resolution drains active streaming escrow reserveEPSS 0.3%CVE-2024-39514HIGHJunos OS and Junos OS Evolved: Receiving specific traffic on devices with EVPN-VPWS with IGMP-snooping enabled will cause the rpd to crashEPSS 0.2%CVE-2023-38420LOWImproper conditions check in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable infEPSS 0.2%CVE-2026-12324HIGHIncorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.2%CVE-2022-0016HIGHGlobalProtect App: Privilege Escalation Vulnerability When Using Connect Before LogonEPSS 0.2%CVE-2021-3433MEDIUMBT: Invalid channel map in CONNECT_IND results to DeadlockEPSS 0.2%CVE-2024-51491LOWProcess crash during CRL-based revocation check on OS using separate mount point for temp Directory in notation-goEPSS 0.2%CVE-2025-59787MEDIUMHTTP 5XX Internal Server ErrorsEPSS 0.2%CVE-2024-0092MEDIUMCVEEPSS 0.2%CVE-2025-12890MEDIUMBluetooth: peripheral: Invalid handling of malformed connection requestEPSS 0.2%CVE-2025-58758MEDIUMTinyEnv: Missing .env file not required — may cause unexpected behaviorEPSS 0.2%