Fallos del tipo CWE-670

110 resultados

Validação inadequada de entrada

Ocorre quando a aplicação não valida ou valida de forma insuficiente dados recebidos de fontes externas (usuário, API, arquivo, rede), permitindo que dados malformados, maliciosos ou inesperados sejam processados. Isso abre porta para injeção, corrupção de lógica e execução de código não autorizado.

Ejemplo

Um formulário web que aceita um campo 'idade' sem verificar se é um número, permite que um atacante envie caracteres especiais ou comandos SQL; ou uma API que recebe um caminho de arquivo sem normalizar ou restringir, deixando vulnerável a path traversal (acesso a arquivos fora do diretório permitido).

Cómo mitigar

Sempre validar entrada no lado do servidor: verificar tipo, comprimento, formato e intervalo esperados. Use listas brancas (whitelist) quando possível, rejeite o que não combina. Combine com sanitização apropriada à saída (escape para HTML, SQL parameterizado, etc.).

CVE-2023-0400MEDIUM The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP contEPSS 0.4%CVE-2026-48844HIGHRoundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could leaEPSS 0.4%CVE-2024-45298MEDIUMDisabled user can bypass lockout by requesting password reset in wiki.jsEPSS 0.4%CVE-2026-32713MEDIUMPX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File DescriptorsEPSS 0.4%CVE-2026-40719HIGHDeadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolvEPSS 0.4%CVE-2026-56307MEDIUMCap-go - Broken Cursor Pagination in /private/devices EndpointEPSS 0.4%CVE-2026-16392CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2026-34946MEDIUMWasmtime's host panics when Winch compiler executes `table.fill`EPSS 0.4%CVE-2022-41884MEDIUMSeg fault in `ndarray_tensor_bridge` due to zero and large inputs in TensorflowEPSS 0.4%CVE-2026-56328HIGHCapgo - Integrity Issue in Release Routing via Multiple Public ChannelsEPSS 0.3%CVE-2026-40396MEDIUMVarnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could sEPSS 0.3%CVE-2026-33011HIGHNest Fastify HEAD Request Middleware BypassEPSS 0.3%CVE-2024-35195MEDIUMRequests `Session` object does not verify requests after making first request with verify=FalseEPSS 0.3%CVE-2024-47168LOWThe `enable_monitoring` flag set to `False` does not disable monitoring in GradioEPSS 0.3%CVE-2026-7656HIGHBroken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stackEPSS 0.3%CVE-2026-26267HIGHrs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collideEPSS 0.3%CVE-2025-2886MEDIUMTerminating targets role delegations are not respected in toughEPSS 0.3%CVE-2025-24800CRITICALCritical vulnerability in `ismp-grandpa` <v15.0.1EPSS 0.3%CVE-2024-5659HIGHRockwell Automation Multicast Request Causes major nonrecoverable fault on Select ControllersEPSS 0.3%CVE-2026-6608MEDIUMlm-sys fastchat Arena Side-by-Side View add_text control flowEPSS 0.3%