Fallos del tipo CWE-120

3166 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2021-1439HIGHCisco Aironet Access Points FlexConnect Multicast DNS Denial of Service VulnerabilityEPSS 0.4%CVE-2018-25294HIGHCEWE Photoshow 6.3.4 Buffer Overflow Denial of ServiceEPSS 0.4%CVE-2024-41217MEDIUMA heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service (DoS) via a crafted EPSS 0.4%CVE-2024-53901MEDIUMThe Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impactEPSS 0.4%CVE-2026-8247HIGHWatchGuard Firebox admd Out of Bounds Write VulnerabilityEPSS 0.4%CVE-2026-21639HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2020-37109MEDIUMaSc TimeTables 2020.11.4 - Denial of ServiceEPSS 0.4%CVE-2020-37206MEDIUMShareAlarmPro Advanced Network Access Control - 'Key' Denial of ServiceEPSS 0.4%CVE-2020-37207MEDIUMSpotDialup 1.6.7 - 'Key' Denial of ServiceEPSS 0.4%CVE-2026-3082HIGHGStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-76703MEDIUMAuthenticated Buffer Overflow Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways Web-Based Management Interface Causes Denial-of-ServiceEPSS 0.4%CVE-2024-48713MEDIUMIn TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stackEPSS 0.4%CVE-2024-48710MEDIUMIn TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stacEPSS 0.4%CVE-2023-49700MEDIUMBuffer Copy Without Checking size of input in IMSEPSS 0.4%CVE-2024-48714MEDIUMIn TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack oEPSS 0.4%CVE-2023-52366HIGHOut-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features tEPSS 0.4%CVE-2026-82479MEDIUMNASA cFS SBN TCP sbn_tcp_if.c OS_read buffer overflowEPSS 0.4%CVE-2025-30265LOWQTS, QuTS heroEPSS 0.4%CVE-2025-67074MEDIUMA Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to causeEPSS 0.4%CVE-2024-48985HIGHAn issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet daEPSS 0.4%