Fallos del tipo CWE-703

174 resultados

Tratamento inadequado de condições excepcionais

É quando o código não verifica ou não lida corretamente com situações de erro, exceção ou estado anômalo. O programa segue adiante como se nada tivesse acontecido, ignorando sinais de falha que deveriam interromper ou redirecionar a execução. Isso pode levar a comportamento imprevisto, vazamento de dados ou falha de segurança.

Ejemplo

Um servidor que recebe uma requisição HTTP não valida; se o parser não verifica o status da leitura e passa dados corrompidos para a próxima camada, a aplicação pode processar lixo como dado legítimo, causando injeção ou bypass de validação.

Cómo mitigar

Sempre verifique o resultado de operações críticas (leitura, alocação, conversão) e implemente blocos catch/finally específicos. Use assertions e logging para detectar estados anômalos cedo, e falhe seguramente (fail-safe) quando algo estiver fora do esperado.

CVE-2021-25366LOWImproper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's autEPSS 0.3%CVE-2023-44203MEDIUMJunos OS: QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLANEPSS 0.3%CVE-2024-37995LOWA vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6EPSS 0.3%CVE-2026-47316MEDIUMImproper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issEPSS 0.3%CVE-2026-34388MEDIUMFleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpointEPSS 0.3%CVE-2026-82417MEDIUMqs.stringify throws TypeError on objects with a non-callable constructor.isBuffer propertyEPSS 0.3%CVE-2021-42205MEDIUMELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a sEPSS 0.3%CVE-2021-25348LOWImproper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorizedEPSS 0.3%CVE-2022-39911MEDIUMImproper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access SamsuEPSS 0.3%CVE-2026-57445HIGHGardens v2: Approve-side dispute resolution drains active streaming escrow reserveEPSS 0.3%CVE-2024-39514HIGHJunos OS and Junos OS Evolved: Receiving specific traffic on devices with EVPN-VPWS with IGMP-snooping enabled will cause the rpd to crashEPSS 0.2%CVE-2023-38420LOWImproper conditions check in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable infEPSS 0.2%CVE-2026-12324HIGHIncorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.2%CVE-2022-0016HIGHGlobalProtect App: Privilege Escalation Vulnerability When Using Connect Before LogonEPSS 0.2%CVE-2021-3433MEDIUMBT: Invalid channel map in CONNECT_IND results to DeadlockEPSS 0.2%CVE-2024-51491LOWProcess crash during CRL-based revocation check on OS using separate mount point for temp Directory in notation-goEPSS 0.2%CVE-2025-59787MEDIUMHTTP 5XX Internal Server ErrorsEPSS 0.2%CVE-2024-0092MEDIUMCVEEPSS 0.2%CVE-2025-12890MEDIUMBluetooth: peripheral: Invalid handling of malformed connection requestEPSS 0.2%CVE-2025-58758MEDIUMTinyEnv: Missing .env file not required — may cause unexpected behaviorEPSS 0.2%