Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2023-52103CRITICALBuffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.EPSS 0.5%CVE-2026-6477HIGHPostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryEPSS 0.5%CVE-2021-23172—A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitabEPSS 0.5%CVE-2024-57483CRITICALTenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.EPSS 0.5%CVE-2025-51630CRITICALTOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the function setIpPortFilterRuEPSS 0.5%CVE-2024-57541MEDIUMLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied to EPSS 0.5%CVE-2023-39409—DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.EPSS 0.5%CVE-2023-41299—DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.EPSS 0.5%CVE-2020-10019HIGHBuffer Overflow in USB DFU requested lengthEPSS 0.5%CVE-2025-25676CRITICALTenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDset function.EPSS 0.4%CVE-2024-46589HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sIpv6AiccuUser parameter at inetipv6.cgi. This vulnerability EPSS 0.4%CVE-2025-25674CRITICALTenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.EPSS 0.4%CVE-2024-46594HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveVPNProfile parameter at v2x00.cgi. This vulnerability allEPSS 0.4%CVE-2024-46582HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sSrvAddr parameter at v2x00.cgi. This vulnerability allows atEPSS 0.4%CVE-2024-37305HIGHBuffer overflow in deserialization in oqs-provider EPSS 0.4%CVE-2024-46586HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sCloudPass parameter at v2x00.cgi. This vulnerability allows EPSS 0.4%CVE-2025-25662CRITICALTenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setMacFilterList via theEPSS 0.4%CVE-2024-46584HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the AControlIp1 parameter at acontrol.cgi. This vulnerability allEPSS 0.4%CVE-2024-46581HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfName parameter at v2x00.cgi. This vulnerability allows aEPSS 0.4%CVE-2024-46597HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPubKey parameter at dialin.cgi. This vulnerability allows atEPSS 0.4%