Fallos del tipo CWE-1021
215 resultadosImplementação inadequada de requisito de segurança
É quando um desenvolvedor implementa um controle de segurança ou funcionalidade crítica de forma incompleta, incorreta ou desalinhada com a intenção original. O código executa, mas não protege contra a ameaça que deveria, deixando brechas exploráveis.
Ejemplo
Um sistema implementa validação de entrada verificando apenas letras, mas esquece de validar tamanho máximo de string. Um atacante envia um payload gigante que causa buffer overflow apesar da validação existir.
Cómo mitigar
Revise a especificação de segurança contra a implementação real (code review com foco em completude). Use testes de segurança específicos (fuzzing, testes de limite) antes de deploy, não confie que 'parece estar protegido'.
CVE-2026-0061MEDIUMIn multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay aEPSS 0.1%CVE-2025-62316LOWHCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configuredEPSS 0.1%CVE-2024-31324HIGHIn hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity in portrait mode firsEPSS 0.1%CVE-2025-48639HIGHIn DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. ThiEPSS 0.1%CVE-2022-20442HIGHIn onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a EPSS 0.1%CVE-2024-43084MEDIUMIn visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information diEPSS 0.1%CVE-2025-32349HIGHIn multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of pEPSS 0.1%CVE-2025-32350HIGHIn maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to a tapjacking/overlaEPSS 0.1%CVE-2025-22417HIGHIn finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. TEPSS 0.1%CVE-2025-48597HIGHIn multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could leEPSS 0.1%CVE-2025-22419HIGHIn multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlaEPSS 0.1%CVE-2026-0036HIGHIn startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to locaEPSS 0.1%CVE-2026-28656HIGHIn multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to lEPSS 0.1%CVE-2026-28577HIGHIn addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to localEPSS 0.1%CVE-2026-84388CRITICALA improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM ChromeEPSS —