Falhas do tipo CWE-229

18 resultados

Tratamento inadequado de valores

Fraqueza genérica que descreve falha em validar, sanitizar ou processar corretamente valores recebidos de entrada, permitindo que dados malformados ou maliciosos causem comportamento inesperado. O risco varia conforme o contexto: pode levar a injeção, desvio de lógica, corrupção de estado ou execução não autorizada.

Exemplo

Um formulário web aceita um campo 'idade' como string sem converter ou validar; um atacante envia 'abc' ou '-999' e causa erro na lógica de negócio que esperava um inteiro válido, resultando em bypass de regras ou crash da aplicação.

Como mitigar

Implemente validação rigorosa na entrada: defina tipos esperados, ranges, formatos e comprimento máximo. Use listas brancas quando possível, rejeite o que não se encaixa, e nunca confie em dados do cliente. Log de rejeições também ajuda a detectar padrões de ataque.

CVE-2022-24412HIGHDell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentEPSS 1.0%CVE-2022-22562HIGHDell PowerScale OneFS, versions 8.2.0-9.3.0, contain a improper handling of missing values exploit. An unauthenticated network attacker coulEPSS 0.9%CVE-2022-4851CRITICALImproper Handling of Values in usememos/memosEPSS 0.8%CVE-2025-59032HIGHManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedEPSS 0.7%CVE-2022-2809HIGHUnauthenticated out of bounds heap write in bmcwebEPSS 0.6%CVE-2022-3409HIGHUnauthenticated out of bounds stack write in bmcwebEPSS 0.6%CVE-2024-36737HIGHImproper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value EPSS 0.5%CVE-2025-20268MEDIUMCisco Secure Firewall Threat Defense Software Geolocation Remote Access VPN Bypass VulnerabilityEPSS 0.5%CVE-2024-39531HIGHJunos OS Evolved: ACX 7000 Series: Protocol specific DDoS configuration affects other protocolsEPSS 0.4%CVE-2024-20431MEDIUMA vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, rEPSS 0.4%CVE-2026-45602CRITICALWindows Dynamic Host Configuration Protocol (DHCP) Tampering VulnerabilityEPSS 0.4%CVE-2025-7964CRITICALZigbee Router Denial of ServiceEPSS 0.3%CVE-2024-29460MEDIUMAn issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point locEPSS 0.2%CVE-2024-0607MEDIUMKernel: nf_tables: pointer math issue in nft_byteorder_eval()EPSS 0.2%CVE-2024-30917MEDIUMAn issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensiEPSS 0.2%CVE-2024-30800MEDIUMPX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.EPSS 0.2%CVE-2025-31648LOWImproper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and EPSS 0.1%CVE-2026-4736HIGHMath Issue in No-Chicken/Echo-MateEPSS 0.1%