Falhas do tipo CWE-754

461 resultados

Falta de validação de condições excepcionais

A fraqueza ocorre quando o software não valida ou valida incorretamente situações anômalas que raramente acontecem durante a operação normal. O desenvolvedor assume que certas condições 'nunca vão acontecer', deixando o código vulnerável quando elas de fato ocorrem — seja por entrada malformada, estado corrompido ou cenários edge case não previstos.

Exemplo

Um parser JSON que só testa o caminho feliz: carrega e processa um JSON válido, mas quando recebe um arquivo com caracteres especiais, tamanho excepcional ou estrutura quebrada, falha silenciosamente ou causa comportamento indefinido em vez de rejeitar explicitamente o entrada inválida.

Como mitigar

Sempre validar entradas e estados, não presumir cenários 'impossíveis': use try-catch, verificações de limites, e testes que explorem casos anormais (fuzzing, boundary testing). Falhe de forma segura e explícita — nunca em silêncio.

CVE-2025-53514MEDIUMUnexpected Input to Server Webhook endpoint Causes DoS in Mattermost Confluence PluginEPSS 0.3%CVE-2026-33801HIGHJunos OS and Junos OS Evolved: When a specifically malformed BGP route update is received RPD crashesEPSS 0.3%CVE-2024-44235MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted coEPSS 0.3%CVE-2025-59958MEDIUMJunos OS Evolved: PTX Series: When a firewall filter rejects traffic these packets are erroneously sent to the REEPSS 0.3%CVE-2024-39869HIGHA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected products allow to upload certificateEPSS 0.3%CVE-2025-14840HIGHHTTP Client Manager - Less critical - Information disclosure - SA-CONTRIB-2025-126EPSS 0.3%CVE-2026-87012MEDIUMOpen WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert valueEPSS 0.3%CVE-2022-45854MEDIUMAn improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to caEPSS 0.3%CVE-2026-19481HIGH@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part headerEPSS 0.3%CVE-2026-87548MEDIUMImproper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictionEPSS 0.3%CVE-2026-4915MEDIUMServer panic via outgoing webhook responsesEPSS 0.3%CVE-2025-52136LOWIn EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is tEPSS 0.3%CVE-2023-28979MEDIUMJunos OS: In a 6PE scenario upon receipt of a specific IPv6 packet an integrity check failsEPSS 0.3%CVE-2026-21910HIGHJunos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic dropEPSS 0.3%CVE-2026-6772HIGHIncorrect boundary conditions in the Libraries component in NSSEPSS 0.3%CVE-2026-57020HIGHJunos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfaces causes a multicast floodEPSS 0.3%CVE-2026-65838HIGHSkipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego policies fail OPEN while the full payload reaches upstreamEPSS 0.3%CVE-2026-47315MEDIUMImproper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issEPSS 0.3%CVE-2026-40069HIGHbsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcastsEPSS 0.3%CVE-2023-41304Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window EPSS 0.3%