Fallos del tipo CWE-754

461 resultados

Falta de verificação de condições excepcionais

O software não valida ou valida incorretamente situações anormais que raramente ocorrem no operação rotineira, deixando o código vulnerável quando essas condições inesperadas acontecem. Isso causa comportamento indefinido, crash ou exploração, porque o desenvolvedor assumiu que 'isso nunca vai acontecer' sem proteção.

Ejemplo

Um parser de arquivo de imagem assume que o header sempre terá exatamente 256 bytes sem checar o tamanho real; quando recebe um arquivo malformado com header menor, acessa memória além do esperado causando leitura fora de limites ou corrupção.

Cómo mitigar

Valide explicitamente todas as entradas e estados críticos, mesmo aqueles aparentemente impossíveis: use asserções em desenvolvimento, trate exceções esperadas e adicione limites de segurança (timeouts, limites de tamanho). Teste com entradas malformadas e corner cases, não apenas fluxo feliz.

CVE-2026-75595CRITICALNetty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContextEPSS 0.3%CVE-2024-44235MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted coEPSS 0.3%CVE-2026-33801HIGHJunos OS and Junos OS Evolved: When a specifically malformed BGP route update is received RPD crashesEPSS 0.3%CVE-2025-59958MEDIUMJunos OS Evolved: PTX Series: When a firewall filter rejects traffic these packets are erroneously sent to the REEPSS 0.3%CVE-2024-39869HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected products allow to upload certificateEPSS 0.3%CVE-2026-87012MEDIUMOpen WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert valueEPSS 0.3%CVE-2025-14840HIGHHTTP Client Manager - Less critical - Information disclosure - SA-CONTRIB-2025-126EPSS 0.3%CVE-2022-45854MEDIUMAn improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to caEPSS 0.3%CVE-2026-19481HIGH@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part headerEPSS 0.3%CVE-2026-4915MEDIUMServer panic via outgoing webhook responsesEPSS 0.3%CVE-2026-87548MEDIUMImproper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictionEPSS 0.3%CVE-2025-52136LOWIn EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is tEPSS 0.3%CVE-2023-28979MEDIUMJunos OS: In a 6PE scenario upon receipt of a specific IPv6 packet an integrity check failsEPSS 0.3%CVE-2026-21910HIGHJunos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic dropEPSS 0.3%CVE-2026-6772HIGHIncorrect boundary conditions in the Libraries component in NSSEPSS 0.3%CVE-2026-57020HIGHJunos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfaces causes a multicast floodEPSS 0.3%CVE-2026-65838HIGHSkipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego policies fail OPEN while the full payload reaches upstreamEPSS 0.3%CVE-2023-41304Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window EPSS 0.3%CVE-2026-40069HIGHbsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcastsEPSS 0.3%CVE-2026-47315MEDIUMImproper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issEPSS 0.3%