Fallos del tipo CWE-451

345 resultados

Representação enganosa de informações críticas na interface

A aplicação apresenta informações de segurança ou avisos críticos de forma desorientadora, oculta ou disfarçada na UI, levando o usuário a tomar decisões perigosas sem compreender as consequências reais. O atacante explora isso para contornar decisões conscientes do usuário, como consentir a execução de código malicioso ou compartilhar dados sensíveis.

Ejemplo

Um navegador que exibe um aviso de certificado inválido em texto pequeno e cinzento no rodapé da página, enquanto mantém o resto do site completamente funcional e destacado, fazendo o usuário ignorar o risco e prosseguir. Ou um app que solicita permissão de câmera com a frase 'Necessário para melhor experiência' escondida em letras minúsculas, sem deixar claro que gravará vídeo.

Cómo mitigar

Deixe avisos e informações críticas de segurança visíveis, legíveis e sem ambiguidade: use cores de contraste alto, fonte adequada, posicionamento central, e linguagem clara. Exija confirmação explícita do usuário antes de ações perigosas e mostre exatamente o que será feito — nunca ocultando ou minimizando os riscos na apresentação.

CVE-2024-38112HIGHWindows MSHTML Platform Spoofing VulnerabilityEPSS 84.2%KEVCVE-2025-9491MEDIUMMicrosoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityEPSS 68.9%CVE-2024-43461HIGHWindows MSHTML Platform Spoofing VulnerabilityEPSS 51.9%KEVCVE-2024-38197MEDIUMMicrosoft Teams for iOS Spoofing VulnerabilityEPSS 16.1%CVE-2024-49040HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 7.7%CVE-2026-0907CRITICALIncorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HEPSS 7.7%CVE-2026-21527MEDIUMMicrosoft Exchange Server Spoofing VulnerabilityEPSS 7.7%CVE-2022-32816MEDIUMThe issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 1EPSS 6.7%CVE-2016-9467Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The locatiEPSS 3.0%CVE-2024-55889MEDIUMphpMyFAQ Vulnerable to Unintended File Download Triggered by Embedded FramesEPSS 2.2%CVE-2016-9468Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exceptioEPSS 2.1%CVE-2016-9473Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trEPSS 1.9%CVE-2020-10775An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbEPSS 1.8%CVE-2022-23646MEDIUMImproper CSP in Image Optimization API for Next.jsEPSS 1.8%CVE-2016-9460Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location barEPSS 1.7%CVE-2017-0888Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayedEPSS 1.5%CVE-2025-21314MEDIUMWindows SmartScreen Spoofing VulnerabilityEPSS 1.4%CVE-2025-21253MEDIUMMicrosoft Edge for IOS and Android Spoofing VulnerabilityEPSS 1.2%CVE-2021-41598UI misrepresentation of granted permissions in GitHub Enterprise Server leading to unauthorized access to userEPSS 1.2%CVE-2025-21259MEDIUMMicrosoft Outlook Spoofing VulnerabilityEPSS 1.1%