Falhas do tipo CWE-664

52 resultados

Controle inadequado de recurso durante seu ciclo de vida

É quando o código não gerencia corretamente a alocação, uso e liberação de um recurso (memória, arquivo, conexão de rede, etc.) do início ao fim de sua existência. O recurso pode vazar, ser acessado após liberação, ou ficar em estado inconsistente, criando brechas de segurança e instabilidade.

Exemplo

Uma aplicação abre uma conexão de banco de dados em uma função, usa para fazer uma query, mas se uma exceção ocorrer antes do close(), a conexão nunca é fechada. Se isso acontecer repetidamente, o pool de conexões se esgota e ninguém mais consegue acessar o banco.

Como mitigar

Use sempre mecanismos de limpeza garantida: try-finally, context managers (with em Python, try-with-resources em Java), destructores confiáveis. Implemente testes que forçam exceções em pontos críticos para validar que recursos são liberados mesmo com falhas.

CVE-2025-21593HIGHJunos OS and Junos OS Evolved: On SRv6 enabled devices, an attacker sending a malformed BGP update can cause the rpd to crashEPSS 0.2%CVE-2026-79603MEDIUMUnconditionally do TLB flushing ahead of page scrubbingEPSS 0.2%CVE-2026-79289LOWImproper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had comEPSS 0.2%CVE-2020-36774MEDIUMplugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to EPSS 0.2%CVE-2026-20336HIGHCisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Resource Lifetime Management VulnerabilitiesEPSS 0.2%CVE-2026-8582MEDIUMObject lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive informatioEPSS 0.2%CVE-2026-64721MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6,EPSS 0.2%CVE-2026-19380MEDIUMMullvad wireguard.sys IOCTL AdapterState reference countEPSS 0.1%CVE-2025-54612MEDIUMIterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stabEPSS 0.1%CVE-2025-54613MEDIUMIterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stabEPSS 0.1%CVE-2025-54619MEDIUMIterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures andEPSS 0.1%CVE-2025-54621MEDIUMIterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.EPSS 0.1%