Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-0077HIGHIn resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the cEPSS 0.1%CVE-2026-0189HIGHIn ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2025-22431MEDIUMIn multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due EPSS 0.1%CVE-2026-56881HIGHIn enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2026-56941HIGHIn multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalaEPSS 0.1%CVE-2025-48649HIGHIn multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead toEPSS 0.1%CVE-2026-56979MEDIUMIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2026-55302MEDIUMIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2026-55304MEDIUMIn addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to localEPSS 0.1%CVE-2026-0187MEDIUMIn gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could leadEPSS 0.1%CVE-2026-0186MEDIUMIn ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalEPSS 0.1%CVE-2026-58755MEDIUMIn smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead tEPSS 0.1%CVE-2026-28612HIGHIn resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. EPSS 0.1%CVE-2026-56973MEDIUMIn multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2026-56970HIGHIn multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of priviEPSS 0.1%CVE-2026-28594HIGHIn multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilegeEPSS 0.1%CVE-2026-28642HIGHIn executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead EPSS 0.1%CVE-2026-28655HIGHIn multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This coulEPSS 0.1%CVE-2026-28634HIGHIn handleUssdRequest of PhoneInterfaceManager.java, there is a possible way to send a USSD request without permission due to a logic error iEPSS 0.1%CVE-2026-58678HIGHIn Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege withEPSS 0.1%