Falhas do tipo CWE-693

839 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-28912HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Tahoe 26.6. EPSS 0.2%CVE-2026-84578HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app EPSS 0.2%CVE-2024-24980MEDIUMProtection mechanism failure in some 3rd, 4th, and 5th Generation Intel(R) Xeon(R) Processors may allow a privileged user to potentially enaEPSS 0.2%CVE-2026-28914MEDIUMA logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.EPSS 0.2%CVE-2026-58052MEDIUM7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name CollisionEPSS 0.2%CVE-2021-26355MEDIUMInsufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in EPSS 0.2%CVE-2024-51481LOWNix allows macOS sandbox escape via built-in buildersEPSS 0.2%CVE-2026-7937LOWInsufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a maEPSS 0.2%CVE-2026-11266MEDIUMInappropriate implementation in SafeBrowsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass Safe Browsing via aEPSS 0.2%CVE-2025-0575LOWUnion Bank of India Vyom Rooting Detection protection mechanismEPSS 0.2%CVE-2026-64708MEDIUMA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2026-65369MEDIUMA logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.EPSS 0.2%CVE-2025-14095MEDIUMPrivilege boundary violation in Radiometer ProductsEPSS 0.2%CVE-2026-92074HIGHMitigation bypass in the Popup Blocker componentEPSS 0.2%CVE-2026-11684LOWInsufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utilitEPSS 0.2%CVE-2024-38660LOWProtection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated user to potentially eEPSS 0.2%CVE-2025-12906MEDIUMInappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2026-28899MEDIUMA logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS TEPSS 0.2%CVE-2025-66479LOWAnthropic Sandbox Runtime Incorrectly Implemented Network SandboxingEPSS 0.2%CVE-2026-17919MEDIUMInsufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege eEPSS 0.2%