Fallos del tipo CWE-440

44 resultados

Violação de Comportamento Esperado

É quando o software faz algo diferente do que deveria fazer conforme sua especificação ou contrato — seja por lógica errada, tratamento inadequado de casos extremos ou falha em validações críticas. O perigo está em que a aplicação pode se comportar de forma impredizível em produção, abrindo brechas para exploração ou corrupção de dados.

Ejemplo

Um sistema bancário que deveria rejeitar transações acima de um limite diário, mas por erro de lógica as aprova mesmo assim. Ou um controle de acesso que deixa passar permissões quando a validação falha, em vez de negar por padrão.

Cómo mitigar

Implemente testes unitários e de integração que cubram comportamentos esperados e casos extremos; use especificações formais ou contratos (como assertions) no código; revise lógica condicional crítica em code review focando em 'o que deveria acontecer aqui?'.

CVE-2020-10768MEDIUMA flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation afteEPSS 0.4%CVE-2026-35040MEDIUMfast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)EPSS 0.4%CVE-2024-47762MEDIUMUnexpected visibility of environment variable configurations in @backstage/plugin-app-backendEPSS 0.4%CVE-2020-10767MEDIUMA flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPEPSS 0.4%CVE-2025-27094MEDIUMTuleap allows default values to be cleared from field configurationEPSS 0.4%CVE-2025-27401MEDIUMIn Tuleap, deleting a report can delete criteria filters in other reportsEPSS 0.3%CVE-2025-6211MEDIUMMD5 Hash Collision in run-llama/llama_indexEPSS 0.3%CVE-2025-52953HIGHJunos OS and Junos OS Evolved: An unauthenticated adjacent attacker sending a valid BGP UPDATE packet forces a BGP session resetEPSS 0.3%CVE-2025-3044MEDIUMMD5 Hash Collision in run-llama/llama_indexEPSS 0.3%CVE-2026-41136MEDIUMfree5GC AMF missing default case in Content-Type switch in HTTPUEContextTransferEPSS 0.3%CVE-2026-3344MEDIUMWatchGuard Firebox System Integrity Check BypassEPSS 0.3%CVE-2023-26819LOWcJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,99999999999999999999999999999999999EPSS 0.2%CVE-2024-7246MEDIUMHPACK table poisoning in gRPC C++, Python & RubyEPSS 0.2%CVE-2026-42752MEDIUMWordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerabilityEPSS 0.2%CVE-2022-3344MEDIUMA flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a coopEPSS 0.2%CVE-2025-40555MEDIUMA vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sending unsolicited BACnetEPSS 0.2%CVE-2025-32728MEDIUMIn sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent EPSS 0.2%CVE-2024-8690MEDIUMCortex XDR Agent: Local Windows Administrator Can Disable the AgentEPSS 0.2%CVE-2026-49316MEDIUMIndian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdownEPSS 0.2%CVE-2026-65932MEDIUMBT122 stops advertisingEPSS 0.2%