Falhas do tipo CWE-668

235 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) através de canais inadequados: mensagens de erro verbosas, logs acessíveis, memória não limpa, headers HTTP desnecessários ou comportamentos diferenciados que vazam pistas. O risco está em que um atacante consegue reunir informações que facilitam outros ataques ou violam privacidade.

Exemplo

Um endpoint retorna 'Usuário não encontrado no banco de dados' em vez de apenas 'Credenciais inválidas', permitindo que alguém enumere usuários válidos; ou a aplicação deixa tokens JWT em cookies acessíveis ao JavaScript malicioso; ou logs de erro com stack traces são servidos publicamente.

Como mitigar

Sanitize mensagens de erro (respostas genéricas ao usuário final, logs detalhados apenas em backend seguro); revise headers HTTP (remova versões de software, X-Powered-By); nunca armazene segredos em código-fonte, variáveis de ambiente ou comentários; implemente rotação e expiração de tokens; configure logs com controle de acesso restrito e sem dados sensíveis em strings de debug.

CVE-2018-8861Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 andEPSS 0.4%CVE-2026-27466HIGHBigBlueButton: Exposed ClamAV port enables Denial of ServiceEPSS 0.4%CVE-2019-13546In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an uEPSS 0.4%CVE-2024-39553MEDIUMJunos OS Evolved: Receipt of arbitrary data when sampling service is enabled, leads to partial Denial of Service (DoS).EPSS 0.4%CVE-2026-59835HIGHA exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may alloEPSS 0.4%CVE-2022-38474MEDIUMA website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not alloEPSS 0.4%CVE-2023-29192LOWSilverwareGames.io users with access to the game upload panel are able to edit download links for games uploaded by other developersEPSS 0.4%CVE-2024-21597MEDIUMJunos OS: MX Series: In an AF scenario traffic can bypass configured lo0 firewall filtersEPSS 0.4%CVE-2025-21608MEDIUMForged packets over MQTT can show up in direct messages in Meshtastic firmwareEPSS 0.4%CVE-2025-61917HIGHn8n Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task RunnerEPSS 0.4%CVE-2020-16212Philips Patient Monitoring Devices Exposure of Resource to Wrong SphereEPSS 0.4%CVE-2024-5313MEDIUMCWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This doEPSS 0.4%CVE-2022-45935MEDIUMApache James server: Temporary File Information DisclosureEPSS 0.4%CVE-2026-67427HIGHFlyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedEPSS 0.4%CVE-2023-2622LOW Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup servicEPSS 0.4%CVE-2024-32473MEDIUMMoby IPv6 enabled on IPv4-only network interfacesEPSS 0.4%CVE-2021-39212MEDIUMIssue when Configuring the ImageMagick Security PolicyEPSS 0.4%CVE-2025-25176CRITICALGPU DDK - GPU Register value contents leaked from secure workloads to non-secure worldEPSS 0.4%CVE-2024-24562MEDIUMSecurity headers not set in vantage6-UIEPSS 0.3%CVE-2026-8958HIGHInformation disclosure, sandbox escape in the Security: Process Sandboxing componentEPSS 0.3%