Falhas do tipo CWE-703

174 resultados

Tratamento inadequado de condições excepcionais

O código não verifica ou trata corretamente situações de erro e exceções, permitindo que o programa continue com um estado inválido ou imprevisível. Isso pode levar a comportamentos inesperados, falhas de segurança ou exposição de informações sensíveis quando algo sai do planejado.

Exemplo

Uma aplicação web tenta conectar a um banco de dados remoto, mas se a conexão falhar, o código não trata a exceção e continua executando, usando uma variável de conexão nula. O resultado é um crash que revela detalhes da infraestrutura ao usuário, ou a execução de lógica com dados corrompidos.

Como mitigar

Sempre use try-catch ou mecanismos equivalentes para capturar exceções. Implemente uma estratégia de tratamento explícito: log do erro (sem expor detalhes sensíveis), rollback de operações incompletas e retorno de uma resposta segura ao usuário. Faça testes com cenários de falha.

CVE-2026-51600HIGHTenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY mEPSS 0.6%CVE-2025-43458MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iEPSS 0.6%CVE-2023-35867MEDIUMAn improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker toEPSS 0.6%CVE-2023-34348HIGHImproper Check or Handling of Exceptional Conditions in Aveva PI Server EPSS 0.6%CVE-2024-21525HIGHAll versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the sourcEPSS 0.5%CVE-2022-30738MEDIUMImproper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.EPSS 0.5%CVE-2022-41589HIGHThe DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling.Successful exploitation of this vulnerability affectEPSS 0.5%CVE-2025-43427MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, EPSS 0.5%CVE-2021-0221MEDIUMJunos OS: QFX Series: Traffic loop Denial of Service (DoS) upon receipt of specific IP multicast trafficEPSS 0.5%CVE-2024-4611HIGHAppPresser <= 4.3.2 - Improper Missing Encryption Exception Handling to Authentication BypassEPSS 0.5%CVE-2023-21036MEDIUMIn BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernEPSS 0.5%CVE-2026-56338MEDIUMCapgo - Denial of Service in 2FA Email Verification via /auth/v1/otp EndpointEPSS 0.5%CVE-2024-6468HIGHVault Vulnerable to Denial of Service When Setting a Proxy Protocol BehaviorEPSS 0.5%CVE-2024-55548MEDIUMDenial of ServiceEPSS 0.5%CVE-2025-14874HIGHNodemailer: nodemailer: denial of service via crafted email address headerEPSS 0.5%CVE-2026-65332MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65337MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65351MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65331MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%CVE-2026-65340MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1EPSS 0.5%