Fallos del tipo CWE-1395

48 resultados

Dependência de Componente Externo Vulnerável

Ocorre quando sua aplicação usa uma biblioteca, framework ou dependência de terceiros que contém vulnerabilidades conhecidas. O risco é que um atacante explore essas falhas no componente externo para comprometer sua aplicação, mesmo que seu código próprio esteja seguro.

Ejemplo

Uma aplicação web que usa uma versão antiga da biblioteca Log4j (anterior à correção do Log4Shell) e não faz atualização. Um atacante injeta um payload malicioso que explora a vulnerabilidade na biblioteca, conseguindo RCE no servidor, independentemente de como o desenvolvedor implementou o resto do código.

Cómo mitigar

Mantenha um inventário de todas as dependências, use ferramentas de scanning (OWASP Dependency-Check, npm audit, Snyk) em CI/CD para detectar versões vulneráveis, atualize regularmente bibliotecas e defina uma política de patching rápido para componentes com CVEs críticas.

CVE-2024-5246HIGHNETGEAR ProSAFE Network Management System Tomcat Remote Code Execution VulnerabilityEPSS 31.3%CVE-2024-38526NONEpdoc embeds link to malicious CDN if math mode is enabledEPSS 3.8%CVE-2024-21421HIGHAzure SDK Spoofing VulnerabilityEPSS 1.8%CVE-2024-11948CRITICALGFI Archiver Telerik Web UI Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-0552CRITICALIntumit inc. SmartRobot - Remote Code ExecutionEPSS 1.2%CVE-2026-23654HIGHGitHub: Zero Shot SCFoundation Remote Code Execution VulnerabilityEPSS 0.9%CVE-2025-34203CRITICALVasion Print (formerly PrinterLogic) Use of Outdated, End-Of-Life, and Vulnerable Third-Party ComponentsEPSS 0.8%CVE-2026-16634CRITICALTOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99EPSS 0.8%CVE-2023-5332MEDIUMDependency on Vulnerable Third-Party Component in GitLabEPSS 0.7%CVE-2026-4176CRITICALPerl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::ZlibEPSS 0.7%CVE-2026-34654MEDIUMAdobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)EPSS 0.6%CVE-2025-40907MEDIUMFCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) libraryEPSS 0.6%CVE-2025-15638CRITICALNet::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcryptEPSS 0.6%CVE-2025-40906CRITICALBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilitiesEPSS 0.6%CVE-2025-10226CRITICALPostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier to Address Multiple VulnerabilitiesEPSS 0.6%CVE-2020-36846CRITICALIO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C libraryEPSS 0.6%CVE-2026-3381CRITICALCompress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlibEPSS 0.5%CVE-2026-34652HIGHAdobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)EPSS 0.5%CVE-2025-40914CRITICALPerl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflowEPSS 0.5%CVE-2026-0943HIGHHarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerabilityEPSS 0.4%