Fallos del tipo CWE-20

5463 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-55273HIGHIn AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to EPSS 0.1%CVE-2025-48651MEDIUMIn importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validatioEPSS 0.1%CVE-2026-58744HIGHIn multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of EPSS 0.1%CVE-2023-20637MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2024-23707HIGHIn multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of priviEPSS 0.1%CVE-2023-20639MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2023-20641MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2023-20638MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2023-20642MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2023-20643MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2025-22432MEDIUMIn notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could leEPSS 0.1%CVE-2023-32826MEDIUMIn camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privEPSS 0.1%CVE-2022-30726MEDIUMUnprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackEPSS 0.1%CVE-2023-20636MEDIUMIn display drm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege withEPSS 0.1%CVE-2023-20640MEDIUMIn ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2023-20650MEDIUMIn apu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2026-28613HIGHIn initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This couldEPSS 0.1%CVE-2025-36932HIGHIn tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validatiEPSS 0.1%CVE-2023-32827MEDIUMIn camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privEPSS 0.1%CVE-2022-33729MEDIUMImproper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connecEPSS 0.1%