Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-17899HIGHInsufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a maEPSS 0.2%CVE-2026-17079MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.2%CVE-2025-59849MEDIUMHCL BigFix Remote Control is vulnerable to an insecure CSP configurationEPSS 0.2%CVE-2026-12031HIGHInappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the EPSS 0.2%CVE-2023-25945MEDIUMProtection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escaEPSS 0.2%CVE-2025-48571MEDIUMIn multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. ThiEPSS 0.2%CVE-2026-6763MEDIUMMitigation bypass in the File Handling componentEPSS 0.2%CVE-2024-36287LOWBypass of TCC restrictions on macOSEPSS 0.2%CVE-2026-94251MEDIUMApache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resourceEPSS 0.2%CVE-2025-31189HIGHA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS VenturaEPSS 0.2%CVE-2023-42938HIGHA logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevateEPSS 0.2%CVE-2026-64708MEDIUMA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2026-24868MEDIUMMitigation bypass in the Privacy: Anti-Tracking componentEPSS 0.2%CVE-2026-17882MEDIUMPolicy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extensioEPSS 0.2%CVE-2025-31244HIGHA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out ofEPSS 0.2%CVE-2026-7909LOWInappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2026-11292MEDIUMInsufficient policy enforcement in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policyEPSS 0.2%CVE-2023-25080MEDIUMProtection mechanism failure in some Intel(R) Distribution of OpenVINO toolkit software before version 2023.0.0 may allow an authenticated uEPSS 0.2%CVE-2026-53845LOWOpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call Hook SkippingEPSS 0.2%CVE-2026-40311MEDIUMImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing valuesEPSS 0.2%