Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-84520CRITICALA buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attacker may be able to EPSS 0.4%CVE-2015-0843CRITICALyubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.EPSS 0.4%CVE-2026-12246HIGHOut of bounds stack write with crafted APL RREPSS 0.4%CVE-2026-76651MEDIUMPre-Authentication Multipart Boundary Buffer Overflow in HTTP Service in TP-Link TL-WR841NEPSS 0.4%CVE-2024-34057HIGHTriangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. TheEPSS 0.4%CVE-2023-28561CRITICALBuffer Copy Without Checking Size of Input in QESLEPSS 0.4%CVE-2023-54328MEDIUMAimOne Video Converter 2.04 Build 103 Buffer Overflow in Registration FormEPSS 0.4%CVE-2025-26005CRITICALTelesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.EPSS 0.4%CVE-2025-26008CRITICALIn Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHosEPSS 0.4%CVE-2025-26007CRITICALTelesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.EPSS 0.4%CVE-2025-26011CRITICALTelesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePasswoEPSS 0.4%CVE-2026-6730CRITICALMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.4%CVE-2025-26006CRITICALTelesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.EPSS 0.4%CVE-2025-26004CRITICALTelesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDEPSS 0.4%CVE-2023-28582CRITICALBuffer Copy Without Checking Size of Input in Data ModemEPSS 0.4%CVE-2023-50268MEDIUMjq has stack-based buffer overflow in decNaNsEPSS 0.4%CVE-2023-6881HIGHfs: fuse: buffer overflow vulnerability in the Zephyr FSEPSS 0.4%CVE-2026-28934MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe EPSS 0.4%CVE-2023-38583HIGHA stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially craftEPSS 0.4%CVE-2025-55611CRITICALD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.EPSS 0.4%