Fallos del tipo CWE-1287

160 resultados

Validação inadequada do tipo de entrada

A aplicação falha em validar corretamente se a entrada recebida pertence ao tipo de dado esperado (string, inteiro, boolean, etc.) antes de usá-la. Isso permite que um atacante envie dados do tipo errado, causando comportamento inesperado, contorno de lógica de negócio ou execução de código malicioso.

Ejemplo

Um formulário de cadastro espera um CPF (string numérica), mas não valida o tipo; um atacante envia um objeto JSON ou um booleano no lugar. A aplicação tenta processar isso sem validação de tipo e acaba executando operações não previstas, como contorno de autenticação ou injeção de dados.

Cómo mitigar

Implemente validação explícita de tipo de entrada na camada de entrada (validadores, parsers com type-checking) e use linguagens ou frameworks com type hints/type checking rigoroso. Para APIs, documente e valide os tipos esperados em cada parâmetro antes de qualquer processamento lógico.

CVE-2021-44694MEDIUMAffected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a deniEPSS 0.6%CVE-2025-20033MEDIUMDoS via custom post type for sysconsole plugin readersEPSS 0.6%CVE-2025-20630MEDIUMMobile crash via object that can't be cast to String in Attachment FieldEPSS 0.6%CVE-2026-55124MEDIUMMicrosoft Word Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-48858HIGHVulnerabilities in TIFF and PCX Image Codecs Impact QNX Software Development PlatformEPSS 0.6%CVE-2025-20088MEDIUMInsufficient Input Validation on Post PropsEPSS 0.6%CVE-2026-4598HIGHVersions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInEPSS 0.5%CVE-2026-29645HIGHNEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV) decoder. The decodeEPSS 0.5%CVE-2024-30395HIGHJunos OS and Junos OS Evolved: A malformed BGP tunnel encapsulation attribute will lead to an rpd crashEPSS 0.5%CVE-2024-48851HIGHRemote Code ExecutionEPSS 0.5%CVE-2026-18830HIGHInsufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness APIEPSS 0.5%CVE-2025-20036MEDIUMInsufficient Input Validation on Post PropsEPSS 0.5%CVE-2025-21083MEDIUMInsufficient Input Validation on Post PropsEPSS 0.5%CVE-2024-35213CRITICALVulnerability in SGI Image Codec Impacts BlackBerry QNX Software Development Platform (SDP)EPSS 0.5%CVE-2024-20494HIGHA vulnerability in the TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat DefenseEPSS 0.5%CVE-2026-21932HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JaEPSS 0.5%CVE-2025-20244HIGHCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access VPN Web Server Denial of Service VulnerabilityEPSS 0.5%CVE-2025-24335LOWSOAP message input validation fault could in theory cause OAM service resource exhaustionEPSS 0.5%CVE-2025-41650HIGHWeidmueller: Denial-of-Service Vulnerability in Industrial Ethernet SwitchesEPSS 0.5%CVE-2025-24876HIGHAuthentication bypass via authorization code injection in SAP ApprouterEPSS 0.5%