Falhas do tipo CWE-451

387 resultados

Má representação de informações críticas na interface

A aplicação exibe informações de segurança críticas de forma enganosa, confusa ou incompleta na interface do usuário. Isso leva o usuário a tomar decisões perigosas — como confiar em dados falsos, ignorar avisos reais ou autorizar operações maliciosas — porque a UI não comunica o risco com clareza.

Exemplo

Um navegador que mostra um aviso de certificado SSL inválido em letras minúsculas cinzentas no rodapé da página, enquanto a barra de endereço verde continua exibindo cadeado. Ou um aplicativo bancário que não deixa evidente se uma transação é reversível ou definitiva, levando o usuário a confirmar uma transferência irreversível sem entender as consequências.

Como mitigar

Destaque informações críticas (avisos, confirmações, mudanças de estado) com contraste visual alto, ícones claros e mensagens em linguagem simples. Implemente confirmações explícitas para operações irreversíveis e testes de usabilidade com usuários reais para validar se entendem os riscos antes de agir.

CVE-2024-6999MEDIUMInappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in spEPSS 0.5%CVE-2025-49755MEDIUMMicrosoft Edge (Chromium-based) for Android Spoofing VulnerabilityEPSS 0.5%CVE-2026-64730MEDIUMThe issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOEPSS 0.5%CVE-2025-46287CRITICALAn inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS EPSS 0.5%CVE-2025-43327MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in Safari 26, macOS Tahoe 26. Visiting a malicious website may lead EPSS 0.5%CVE-2022-20530MEDIUMIn strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call lEPSS 0.5%CVE-2021-27773MEDIUMHCL Sametime is vulnerable to clickjackingEPSS 0.5%CVE-2024-6595LOWUncontrolled Search Path Element in GitLabEPSS 0.5%CVE-2026-79011HIGHUI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass syEPSS 0.4%CVE-2026-26320HIGHOpenClaw macOS deep link confirmation truncation can conceal executed agent messageEPSS 0.4%CVE-2025-62223MEDIUMMicrosoft Edge (Chromium-based) for Mac Spoofing VulnerabilityEPSS 0.4%CVE-2026-45150MEDIUMZen Browser - Missing Fullscreen Security Notification Allows Origin SpoofingEPSS 0.4%CVE-2024-47044MEDIUMMultiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient accessEPSS 0.4%CVE-2025-5065MEDIUMInappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofinEPSS 0.4%CVE-2025-0729MEDIUMTP-Link TL-SG108E clickjackingEPSS 0.4%CVE-2025-5066MEDIUMInappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user tEPSS 0.4%CVE-2020-9236HIGHThere is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some opeEPSS 0.4%CVE-2023-7011MEDIUMInappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents EPSS 0.4%CVE-2025-47964MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.4%CVE-2023-50938MEDIUMIBM PowerSC clickjackingEPSS 0.4%