Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-40311MEDIUMImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing valuesEPSS 0.2%CVE-2025-58406MEDIUMLack of HTTP Response HeadersEPSS 0.2%CVE-2023-34427MEDIUMProtection mechanism failure in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an autEPSS 0.2%CVE-2022-20805MEDIUMCisco Umbrella Secure Web Gateway File Decryption Bypass VulnerabilityEPSS 0.2%CVE-2026-14092MEDIUMInsufficient policy enforcement in Privacy in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to lEPSS 0.2%CVE-2026-11260MEDIUMInappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security polEPSS 0.2%CVE-2026-47624MEDIUMNVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of EPSS 0.2%CVE-2026-11264MEDIUMPolicy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policyEPSS 0.2%CVE-2022-20562LOWIn various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. EPSS 0.2%CVE-2026-55487HIGHpnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycleEPSS 0.2%CVE-2025-46358HIGHEmerson ValveLink Products Protection Mechanism FailureEPSS 0.2%CVE-2026-13601HIGHYelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applicationsEPSS 0.2%CVE-2022-41984MEDIUMProtection mechanism failure for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and DecembeEPSS 0.2%CVE-2024-36242HIGHProtection mechanism failure in the SPP for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of priEPSS 0.2%CVE-2026-11247LOWInsufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-oriEPSS 0.2%CVE-2026-48792MEDIUMpam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling remote desktop detection under non-root executionEPSS 0.2%CVE-2026-11695MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via aEPSS 0.2%CVE-2026-11234MEDIUMInappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendeEPSS 0.2%CVE-2026-61437HIGHPraisonAI before 1.6.78 Remote Code Execution via tools.pyEPSS 0.2%CVE-2026-28912HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Tahoe 26.6. EPSS 0.2%