Fallos del tipo CWE-1104

29 resultados

Uso de componentes de terceiros não mantidos

A aplicação depende de bibliotecas, frameworks ou módulos de terceiros que não recebem mais atualizações de segurança nem correções de bugs. Quando vulnerabilidades são descobertas nesses componentes, a equipe fica exposta porque não há patches disponíveis ou porque atualizá-los é impraticável.

Ejemplo

Uma aplicação Node.js usa uma versão antiga de um parser XML que tinha 5 anos sem atualização. Um CVE é publicado para injeção XXE justamente nesse parser; como o projeto foi abandonado pelos mantenedores, não há correção e a empresa fica vulnerável indefinidamente.

Cómo mitigar

Audite regularmente dependências com ferramentas como SBOM, retire componentes mortos do inventário e migre para alternativas mantidas ativamente. Implemente política de end-of-life claro para dependências e monitore anúncios de segurança dos projetos que usa.

CVE-2023-7102—Remote Code Execution (RCE) VulnerabilityEPSS 44.6%CVE-2024-35252HIGHAzure Storage Movement Client Library Denial of Service VulnerabilityEPSS 2.5%CVE-2021-22142MEDIUMKibana Reporting vulnerabilitiesEPSS 1.0%CVE-2025-34192CRITICALVasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL VersionEPSS 1.0%CVE-2022-46871HIGHAn out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.EPSS 0.9%CVE-2026-16634CRITICALTOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99EPSS 0.8%CVE-2025-34193HIGHVasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and Use Outdated RuntimesEPSS 0.8%CVE-2025-10220CRITICALOutdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4EPSS 0.7%CVE-2026-3031CRITICALImage::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg libraryEPSS 0.7%CVE-2026-11325HIGHcloudflare/pages-action is deprecated — migration required by September 18th, 2026EPSS 0.7%CVE-2026-41468CRITICALBeghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template InjectionEPSS 0.7%CVE-2024-11999HIGHCWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticaEPSS 0.6%CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2024-21631MEDIUMInteger overflow in URI leading to potential host spoofingEPSS 0.6%CVE-2026-60368HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.5%CVE-2026-66788LOWLighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tagEPSS 0.4%CVE-2025-12104CRITICALIncorrect Content-Type HeaderEPSS 0.4%CVE-2025-3497HIGHRadiflow iSAP Smart Collector Linux distribution unmaintainedEPSS 0.3%CVE-2026-12554HIGHHP Easy Start for macOS - Security UpdateEPSS 0.3%CVE-2026-56580LOWHCL MyCloud was affected by Using Components with Known VulnerabilityEPSS 0.3%