Falhas do tipo CWE-754

461 resultados

Falta de validação de condições excepcionais

A fraqueza ocorre quando o software não valida ou valida incorretamente situações anômalas que raramente acontecem durante a operação normal. O desenvolvedor assume que certas condições 'nunca vão acontecer', deixando o código vulnerável quando elas de fato ocorrem — seja por entrada malformada, estado corrompido ou cenários edge case não previstos.

Exemplo

Um parser JSON que só testa o caminho feliz: carrega e processa um JSON válido, mas quando recebe um arquivo com caracteres especiais, tamanho excepcional ou estrutura quebrada, falha silenciosamente ou causa comportamento indefinido em vez de rejeitar explicitamente o entrada inválida.

Como mitigar

Sempre validar entradas e estados, não presumir cenários 'impossíveis': use try-catch, verificações de limites, e testes que explorem casos anormais (fuzzing, boundary testing). Falhe de forma segura e explícita — nunca em silêncio.

CVE-2021-22746Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems thatEPSS 0.2%CVE-2024-39519HIGHJunos OS Evolved: ACX 7000 Series: Multicast traffic is looped in a multihoming EVPN MPLS scenarioEPSS 0.2%CVE-2024-54115MEDIUMOut-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.2%CVE-2024-54116MEDIUMOut-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnoEPSS 0.2%CVE-2021-22745Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems thatEPSS 0.2%CVE-2021-22747Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems thatEPSS 0.2%CVE-2026-73288MEDIUMRustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deletedEPSS 0.2%CVE-2022-47111LOW7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffectEPSS 0.2%CVE-2026-4054MEDIUMSVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of serviceEPSS 0.2%CVE-2026-34066MEDIUMnimiq-blockchain: Peer-triggerable panic during history syncEPSS 0.2%CVE-2026-39395MEDIUMCosign's verify-blob-attestation reports false positive when payload parsing failsEPSS 0.2%CVE-2023-44196MEDIUMJunos OS Evolved: PTX10003 Series: Packets which are not destined to the router can reach the REEPSS 0.2%CVE-2021-33147MEDIUMImproper conditions check in the Intel(R) IPP Crypto library before version 2021.2 may allow an authenticated user to potentially enable infEPSS 0.2%CVE-2025-8716MEDIUMCache exploitation vulnerabilityEPSS 0.2%CVE-2021-29607MEDIUMIncomplete validation in `SparseSparseMinimum`EPSS 0.2%CVE-2024-50195HIGHposix-clock: Fix missing timespec64 check in pc_clock_settime()EPSS 0.2%CVE-2025-0116MEDIUMPAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP FrameEPSS 0.2%CVE-2024-50184MEDIUMvirtio_pmem: Check device status before requesting flushEPSS 0.2%CVE-2021-22743Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TCM 4351B installed on Tricon V11.3.x systems that couEPSS 0.2%CVE-2026-0269MEDIUMPAN-OS: Denial of Service (DoS) in Tunnel Traffic ProcessingEPSS 0.2%