Falhas do tipo CWE-248

243 resultados

Exceção não capturada

Ocorre quando o código não trata exceções que podem ser lançadas durante a execução, permitindo que erros se propaghem de forma descontrolada. Isso pode expor informações sensíveis em mensagens de erro, causar travamentos inesperados ou deixar a aplicação em estado inconsistente.

Exemplo

Um endpoint de API que tenta conectar a um banco de dados sem try-catch: se a conexão falhar, a exceção não tratada retorna um stack trace completo ao cliente, revelando caminho do servidor, versões de bibliotecas e estrutura interna do código.

Como mitigar

Envolva operações críticas (I/O, rede, parsing) em blocos try-catch apropriados, registre erros adequadamente em logs internos e retorne mensagens de erro genéricas ao usuário. Implemente um handler global de exceções na aplicação para capturar falhas não previstas.

CVE-2023-31125MEDIUMUncaught exception in engine.ioEPSS 1.3%CVE-2016-10363Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX EPSS 1.3%CVE-2020-5129A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP server crash which leaEPSS 1.3%CVE-2022-20675MEDIUMMultiple Cisco Security Products Simple Network Management Protocol Service Denial of Service VulnerabilityEPSS 1.3%CVE-2024-20137HIGHIn wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote deniaEPSS 1.2%CVE-2026-50328HIGHWindows Server Update Service (WSUS) Tampering VulnerabilityEPSS 1.2%CVE-2020-27121MEDIUMCisco Unified Communications Manager IM and Presence Service Denial of Service VulnerabilityEPSS 1.2%CVE-2013-10065HIGHSysax Multi-Server <= 6.10 SSHD Key Exchange DoSEPSS 1.1%CVE-2019-6830A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of serviEPSS 1.1%CVE-2023-2251HIGHUncaught Exception in eemeli/yamlEPSS 1.1%CVE-2022-20919HIGHCisco IOS and IOS XE Software Common Industrial Protocol Request Denial of Service VulnerabilityEPSS 1.1%CVE-2023-22477MEDIUMMercurius is vulnerable to denial of service (DoS) when using subscriptionsEPSS 1.1%CVE-2021-33010HIGHAVEVA System Platform Uncaught ExceptionEPSS 1.1%CVE-2023-3966HIGHOpenvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packetEPSS 1.0%CVE-2023-22941MEDIUMImproperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk DaemonEPSS 1.0%CVE-2022-36046MEDIUMUnexpected server crash in Next.js version 12.2.3EPSS 1.0%CVE-2021-25971MEDIUMCamaleon CMS - SVG File Upload Creates DoS for Media Upload FeatureEPSS 1.0%CVE-2021-32694MEDIUMMalicious Android application can crash the Nextcloud Android ClientEPSS 1.0%CVE-2023-38504HIGHSails DoS vulnerability for apps with sockets enabledEPSS 0.9%CVE-2021-41545A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXEPSS 0.9%