Falhas do tipo CWE-248

291 resultados

Exceção não capturada

Ocorre quando o código não trata exceções que podem ser lançadas durante a execução, permitindo que erros se propaghem de forma descontrolada. Isso pode expor informações sensíveis em mensagens de erro, causar travamentos inesperados ou deixar a aplicação em estado inconsistente.

Exemplo

Um endpoint de API que tenta conectar a um banco de dados sem try-catch: se a conexão falhar, a exceção não tratada retorna um stack trace completo ao cliente, revelando caminho do servidor, versões de bibliotecas e estrutura interna do código.

Como mitigar

Envolva operações críticas (I/O, rede, parsing) em blocos try-catch apropriados, registre erros adequadamente em logs internos e retorne mensagens de erro genéricas ao usuário. Implemente um handler global de exceções na aplicação para capturar falhas não previstas.

CVE-2024-0754MEDIUMSome WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.EPSS 0.4%CVE-2026-55780LOWNanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry SizeEPSS 0.4%CVE-2025-59229MEDIUMMicrosoft Office Denial of Service VulnerabilityEPSS 0.4%CVE-2023-5038HIGHUnauthenticated DoSEPSS 0.4%CVE-2025-43855HIGHtRPC 11 WebSocket DoS VulnerabilityEPSS 0.4%CVE-2026-20068MEDIUMMultiple Cisco Products Snort 3 TBD Denial of Service VulnerabilityEPSS 0.4%CVE-2026-20031MEDIUMClamAV CSS Image Parsing Error Handling Denial of Service VulnerabilityEPSS 0.4%CVE-2025-54134HIGHHAX CMS NodeJs's Improper Error Handling Leads to Denial of ServiceEPSS 0.4%CVE-2025-55553HIGHA syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).EPSS 0.4%CVE-2025-55557HIGHA Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of ServEPSS 0.4%CVE-2026-7183MEDIUMaligungr UERANSIM Radio Link Simulation Layer rls_pdu.cpp DecodeRlsMessage uncaught exceptionEPSS 0.4%CVE-2025-9124HIGHRockwell Automation Compact GuardLogix® 5370 Denial-Of-Service VulnerabilityEPSS 0.4%CVE-2026-42268HIGHModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operatorsEPSS 0.4%CVE-2026-92081MEDIUMfastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responsesEPSS 0.4%CVE-2026-52739MEDIUMZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier RejectionEPSS 0.4%CVE-2026-19534HIGHundici vulnerable to Denial of Service via unrequested WebSocket subprotocolEPSS 0.4%CVE-2026-72813MEDIUMactix-files before 0.6.10 Denial of Service via empty Range headerEPSS 0.4%CVE-2025-36539HIGHAVEVA PI Data Archive Uncaught ExceptionEPSS 0.4%CVE-2023-1691Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause featEPSS 0.4%CVE-2024-28835MEDIUMGnutls: potential crash during chain building/verificationEPSS 0.4%