Fallos del tipo CWE-703

174 resultados

Tratamento inadequado de condições excepcionais

É quando o código não verifica ou não lida corretamente com situações de erro, exceção ou estado anômalo. O programa segue adiante como se nada tivesse acontecido, ignorando sinais de falha que deveriam interromper ou redirecionar a execução. Isso pode levar a comportamento imprevisto, vazamento de dados ou falha de segurança.

Ejemplo

Um servidor que recebe uma requisição HTTP não valida; se o parser não verifica o status da leitura e passa dados corrompidos para a próxima camada, a aplicação pode processar lixo como dado legítimo, causando injeção ou bypass de validação.

Cómo mitigar

Sempre verifique o resultado de operações críticas (leitura, alocação, conversão) e implemente blocos catch/finally específicos. Use assertions e logging para detectar estados anômalos cedo, e falhe seguramente (fail-safe) quando algo estiver fora do esperado.

CVE-2026-51600HIGHTenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY mEPSS 0.6%CVE-2025-43458MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iEPSS 0.6%CVE-2023-35867MEDIUMAn improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker toEPSS 0.6%CVE-2023-34348HIGHImproper Check or Handling of Exceptional Conditions in Aveva PI Server EPSS 0.6%CVE-2024-21525HIGHAll versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the sourcEPSS 0.5%CVE-2022-30738MEDIUMImproper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.EPSS 0.5%CVE-2022-41589HIGHThe DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affectEPSS 0.5%CVE-2025-43427MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, EPSS 0.5%CVE-2021-0221MEDIUMJunos OS: QFX Series: Traffic loop Denial of Service (DoS) upon receipt of specific IP multicast trafficEPSS 0.5%CVE-2024-4611HIGHAppPresser <= 4.3.2 - Improper Missing Encryption Exception Handling to Authentication BypassEPSS 0.5%CVE-2023-21036MEDIUMIn BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernEPSS 0.5%CVE-2026-56338MEDIUMCapgo - Denial of Service in 2FA Email Verification via /auth/v1/otp EndpointEPSS 0.5%CVE-2024-6468HIGHVault Vulnerable to Denial of Service When Setting a Proxy Protocol BehaviorEPSS 0.5%CVE-2024-55548MEDIUMDenial of ServiceEPSS 0.5%CVE-2025-14874HIGHNodemailer: nodemailer: denial of service via crafted email address headerEPSS 0.5%CVE-2026-65332MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65337MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65351MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65331MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65340MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%