Falhas do tipo CWE-755

243 resultados

Tratamento inadequado de condições excepcionais

É quando o código não trata, trata de forma insuficiente ou de forma errada situações de erro e exceções. Isso pode deixar o software em estado inconsistente, ignorar falhas críticas ou executar código perigoso quando algo dá errado, compromentendo segurança, integridade ou disponibilidade.

Exemplo

Um servidor Web recebe uma requisição mal formada e falha ao parsear JSON; em vez de retornar erro 400, simplesmente pula a validação e processa dados vazios, ou uma conexão de banco de dados cai e a aplicação continua operando com dados em cache desatualizado sem avisar o usuário.

Como mitigar

Sempre trate exceções explicitamente: capture erros conhecidos e faça rollback/limpeza apropriada, log de falhas para auditoria, e retorne respostas claras ao usuário. Use type hints e validação de entrada antes de processar, e considere parar o sistema de forma segura se a exceção for crítica.

CVE-2021-0297MEDIUMJunos OS Evolved: BGP and LDP sessions with TCP MD5 authentication established with peers not configured for authenticationEPSS 0.7%CVE-2022-0023MEDIUMPAN-OS: Denial-of-Service (DoS) Vulnerability in DNS ProxyEPSS 0.7%CVE-2023-50728MEDIUMUnauthenticated Denial of Service in the octokit/webhooks libraryEPSS 0.7%CVE-2023-6267HIGHQuarkus: json payload getting processed prior to security checks when rest resources are used with annotations.EPSS 0.7%CVE-2024-30382HIGHJunos OS and Junos OS Evolved: RPD crash when CoS-based forwarding (CBF) policy is configuredEPSS 0.7%CVE-2023-25644MEDIUMDenial of Service Vulnerability in Some ZTE Mobile Internet ProductsEPSS 0.7%CVE-2023-45820MEDIUMDirectus crashes on invalid WebSocket messageEPSS 0.7%CVE-2025-8008HIGHRockwell Automation 1756-ENT2R, EN4TR, EN4TRXT VulnerabilityEPSS 0.7%CVE-2023-48232LOWFloating point Exception in adjust_plines_for_skipcol() in vimEPSS 0.7%CVE-2022-44030HIGHRedmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. DependiEPSS 0.7%CVE-2024-47489MEDIUMJunos OS Evolved: ACX Series: Receipt of specific transit protocol packets is incorrectly processed by the REEPSS 0.7%CVE-2021-38363HIGHAn issue was discovered in ONOS 2.5.1. In IntentManager, the install-requested intent (which causes an exception) remains in pendingMap (in EPSS 0.7%CVE-2023-36832HIGHJunos OS: MX Series: PFE crash upon receipt of specific packet destined to an AMS interfaceEPSS 0.6%CVE-2024-6594HIGHWatchGuard Firebox Single Sign-On Client Denial-of-ServiceEPSS 0.6%CVE-2024-21585MEDIUMJunos OS and Junos OS Evolved: BGP session flaps on NSR-enabled devices can cause rpd crashEPSS 0.6%CVE-2022-39380MEDIUMwire-webapp contains Improper Handling of Exceptional Conditions leading to a DoS via Markdown RenderingEPSS 0.6%CVE-2024-47609MEDIUMRemotely exploitable DoS in Tonic `<=v0.12.2`EPSS 0.6%CVE-2025-27465MEDIUMx86: Incorrect stubs exception handling for flags recoveryEPSS 0.6%CVE-2024-7521CRITICALIncomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14,EPSS 0.6%CVE-2023-24510HIGHOn the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.EPSS 0.6%