Falhas do tipo CWE-1021

215 resultados

Implementação inadequada de mecanismo de segurança

A lógica de segurança foi implementada de forma incompleta ou incorreta, deixando brechas que um atacante pode explorar. É quando o desenvolvedor tenta fazer o certo (validar entrada, criptografar dados, autenticar usuário), mas comete erros na execução que anulam a proteção.

Exemplo

Um sistema implementa autenticação de dois fatores, mas aceita o código OTP mesmo depois de expirado; ou valida se um arquivo é imagem checando apenas a extensão, não o conteúdo real do arquivo.

Como mitigar

Revise a implementação de controles de segurança críticos (autenticação, validação, criptografia) com code review rigoroso e testes de segurança específicos. Use bibliotecas consolidadas em vez de reinventar mecanismos; nunca implemente criptografia ou lógica sensível do zero sem expertise comprovada.

CVE-2026-0061MEDIUMIn multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay aEPSS 0.1%CVE-2025-62316LOWHCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configuredEPSS 0.1%CVE-2024-31324HIGHIn hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity in portrait mode firsEPSS 0.1%CVE-2025-48639HIGHIn DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. ThiEPSS 0.1%CVE-2022-20442HIGHIn onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API level < 23 due to a EPSS 0.1%CVE-2024-43084MEDIUMIn visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information diEPSS 0.1%CVE-2025-32349HIGHIn multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of pEPSS 0.1%CVE-2025-32350HIGHIn maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to a tapjacking/overlaEPSS 0.1%CVE-2025-22417HIGHIn finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. TEPSS 0.1%CVE-2025-48597HIGHIn multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could leEPSS 0.1%CVE-2025-22419HIGHIn multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlaEPSS 0.1%CVE-2026-0036HIGHIn startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to locaEPSS 0.1%CVE-2026-28656HIGHIn multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to lEPSS 0.1%CVE-2026-28577HIGHIn addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to localEPSS 0.1%CVE-2026-84388CRITICALA improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM ChromeEPSS