Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-55611CRITICALD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.EPSS 0.4%CVE-2021-46884HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2021-46881HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2021-34055HIGHjhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.EPSS 0.4%CVE-2022-48497—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2021-46882HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2021-46886HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2024-28565MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the pEPSS 0.4%CVE-2022-48490—Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2021-46885HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2022-48501HIGHConfiguration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.EPSS 0.4%CVE-2021-46883HIGHThe video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availabilitEPSS 0.4%CVE-2025-1368MEDIUMMicroWord eScan Antivirus mwav.conf ReadConfiguration buffer overflowEPSS 0.4%CVE-2021-47798MEDIUMNoteBurner 2.35 - Denial Of Service (DoS) (PoC)EPSS 0.4%CVE-2024-57537MEDIUMLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack withoEPSS 0.4%CVE-2024-22905HIGHBuffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted script to the hciTrSeEPSS 0.4%CVE-2020-14374—A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffeEPSS 0.4%CVE-2024-25373MEDIUMTenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.EPSS 0.4%CVE-2025-12012CRITICALCompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer OverflowEPSS 0.4%CVE-2026-34124HIGHDenial of Service via Path Expansion Overflow in HTTP Service in TP-Link Tapo C520WSEPSS 0.4%