Falhas do tipo CWE-670

101 resultados

Validação inadequada de entrada

A aplicação aceita dados do usuário sem verificar corretamente se estão no formato, tamanho ou conteúdo esperado antes de usá-los. Isso permite que entradas malformadas ou maliciosas causem comportamentos inesperados, desde injeção de código até travamentos.

Exemplo

Um formulário web que recebe um CPF não valida o formato (deve ter 11 dígitos) e passa direto para a query SQL. Um atacante injeta comando SQL disfarçado de CPF, ou um campo de data aceita strings arbitrárias e quebra a lógica de cálculo da aplicação.

Como mitigar

Implemente whitelist de caracteres permitidos, valide tipo e tamanho na entrada, use prepared statements para SQL, e trate erros sem expor detalhes internos. Nunca confie em dados do cliente, mesmo que venham de JavaScript — valide sempre no servidor.

CVE-2021-34767HIGHCisco IOS XE Software for Catalyst 9800 Series Wireless Controllers IPv6 Denial of Service VulnerabilityEPSS 0.8%CVE-2024-32971CRITICALDefect in query plan cache may cause incorrect operations to be executed in Apollo RouterEPSS 0.7%CVE-2023-41376Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP pEPSS 0.7%CVE-2021-32684MEDIUMMissing Handler in @scandipwa/magento-scriptsEPSS 0.7%CVE-2024-53270HIGHHTTP/1: sending overload crashes when the request is reset beforehand in envoyEPSS 0.7%CVE-2024-53269MEDIUMHappy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoyEPSS 0.7%CVE-2025-58136HIGHApache Traffic Server: A simple legitimate POST request causes a crashEPSS 0.7%CVE-2022-29607HIGHAn issue was discovered in ONOS 2.5.1. Modification of an existing intent to have the same source and destination shows the INSTALLED state EPSS 0.7%CVE-2023-20558HIGH Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to EPSS 0.7%CVE-2022-29605HIGHAn issue was discovered in ONOS 2.5.1. IntentManager attempts to install the IPv6 flow rules of an intent into an OpenFlow 1.0 switch that dEPSS 0.7%CVE-2023-23623HIGHContent-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled in ElectronEPSS 0.7%CVE-2025-21607LOWSuccess of Certain Precompile Calls not Checked in VyperEPSS 0.7%CVE-2023-41058HIGHTrigger `beforeFind` not invoked in internal query pipeline in parse-serverEPSS 0.6%CVE-2024-53271HIGHHTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoyEPSS 0.6%CVE-2024-30246HIGHTuleap deleting or moving an artifact can delete values from unrelated artifactsEPSS 0.6%CVE-2024-37153HIGHEvmos's contract balance not updating correctly after interchain transactionEPSS 0.6%CVE-2026-53404HIGHApache Tomcat: Bad ornext processing in RewriteValveEPSS 0.6%CVE-2022-29609MEDIUMAn issue was discovered in ONOS 2.5.1. An intent with the same source and destination shows the INSTALLING state, indicating that its flow rEPSS 0.6%CVE-2025-49091HIGHKDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a sEPSS 0.6%CVE-2024-35190MEDIUMAsterisk' res_pjsip_endpoint_identifier_ip: wrongly matches ALL unauthorized SIP requestsEPSS 0.6%