Fallos del tipo CWE-754

461 resultados

Falta de verificação de condições excepcionais

O software não valida ou valida incorretamente situações anormais que raramente ocorrem no operação rotineira, deixando o código vulnerável quando essas condições inesperadas acontecem. Isso causa comportamento indefinido, crash ou exploração, porque o desenvolvedor assumiu que 'isso nunca vai acontecer' sem proteção.

Ejemplo

Um parser de arquivo de imagem assume que o header sempre terá exatamente 256 bytes sem checar o tamanho real; quando recebe um arquivo malformado com header menor, acessa memória além do esperado causando leitura fora de limites ou corrupção.

Cómo mitigar

Valide explicitamente todas as entradas e estados críticos, mesmo aqueles aparentemente impossíveis: use asserções em desenvolvimento, trate exceções esperadas e adicione limites de segurança (timeouts, limites de tamanho). Teste com entradas malformadas e corner cases, não apenas fluxo feliz.

CVE-2021-22746Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems thatEPSS 0.2%CVE-2024-39519HIGHJunos OS Evolved: ACX 7000 Series: Multicast traffic is looped in a multihoming EVPN MPLS scenarioEPSS 0.2%CVE-2024-54115MEDIUMOut-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.2%CVE-2024-54116MEDIUMOut-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnoEPSS 0.2%CVE-2021-22745Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems thatEPSS 0.2%CVE-2021-22747Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems thatEPSS 0.2%CVE-2026-73288MEDIUMRustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deletedEPSS 0.2%CVE-2022-47111LOW7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffectEPSS 0.2%CVE-2026-4054MEDIUMSVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of serviceEPSS 0.2%CVE-2026-34066MEDIUMnimiq-blockchain: Peer-triggerable panic during history syncEPSS 0.2%CVE-2026-39395MEDIUMCosign's verify-blob-attestation reports false positive when payload parsing failsEPSS 0.2%CVE-2023-44196MEDIUMJunos OS Evolved: PTX10003 Series: Packets which are not destined to the router can reach the REEPSS 0.2%CVE-2021-33147MEDIUMImproper conditions check in the Intel(R) IPP Crypto library before version 2021.2 may allow an authenticated user to potentially enable infEPSS 0.2%CVE-2025-8716MEDIUMCache exploitation vulnerabilityEPSS 0.2%CVE-2021-29607MEDIUMIncomplete validation in `SparseSparseMinimum`EPSS 0.2%CVE-2024-50195HIGHposix-clock: Fix missing timespec64 check in pc_clock_settime()EPSS 0.2%CVE-2025-0116MEDIUMPAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP FrameEPSS 0.2%CVE-2024-50184MEDIUMvirtio_pmem: Check device status before requesting flushEPSS 0.2%CVE-2021-22743Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TCM 4351B installed on Tricon V11.3.x systems that couEPSS 0.2%CVE-2026-0269MEDIUMPAN-OS: Denial of Service (DoS) in Tunnel Traffic ProcessingEPSS 0.2%