Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-28639HIGHIn rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local esEPSS 0.1%CVE-2025-22427HIGHIn onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due tEPSS 0.1%CVE-2025-22437HIGHIn setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in EPSS 0.1%CVE-2025-22434HIGHIn handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could leaEPSS 0.1%CVE-2026-54073MEDIUMVeraCrypt: Hidden volume quick format weakens plausible deniabilityEPSS 0.1%CVE-2025-26458HIGHIn multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic error in the code. ThisEPSS 0.1%CVE-2025-26444HIGHIn onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the defaultEPSS 0.1%CVE-2025-48546HIGHIn checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This couldEPSS 0.1%CVE-2025-26431HIGHIn setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logicEPSS 0.1%CVE-2025-26439HIGHIn getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead ofEPSS 0.1%CVE-2025-36905HIGHIn gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local EPSS 0.1%CVE-2026-0118HIGHIn oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalation of privilege withEPSS 0.1%CVE-2025-36898HIGHThere is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additEPSS 0.1%CVE-2025-48652HIGHIn performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This coulEPSS 0.1%CVE-2026-0045HIGHIn bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. TEPSS 0.1%CVE-2026-28658HIGHIn findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation EPSS 0.1%CVE-2025-48554MEDIUMIn handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the coEPSS 0.1%CVE-2026-0087HIGHIn approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic EPSS 0.1%CVE-2026-0077HIGHIn resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the cEPSS 0.1%CVE-2026-28668HIGHIn LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalatioEPSS 0.1%