Fallos del tipo CWE-120

3166 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2022-47095HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_parse_vps_extension function of media_tools/av_parsers.cEPSS 0.4%CVE-2021-31844HIGHLocal Privilege Escalation in McAfee DLP Endpoint for WindowsEPSS 0.4%CVE-2026-6681LOWPKCS#7 decode ignores caller output buffer size, writing past buffer boundsEPSS 0.4%CVE-2023-40036MEDIUMNotepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneCharEPSS 0.4%CVE-2023-1190MEDIUMxiaozhuai imageinfo imageinfo.hpp buffer overflowEPSS 0.4%CVE-2024-24192LOWrobdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.EPSS 0.4%CVE-2023-50008HIGHFFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9EPSS 0.4%CVE-2025-3763MEDIUMSourceCodester Phone Management System Password main buffer overflowEPSS 0.4%CVE-2025-24003HIGHMQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging StationsEPSS 0.4%CVE-2024-24456MEDIUMAn E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentially due to a buffer EPSS 0.4%CVE-2025-41418MEDIUMBuffer Overflow vulnerability exists in multiple versions of TB-eye network recorders and AHD recorders. The CGI process may be terminated aEPSS 0.4%CVE-2026-58710HIGHIn DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remEPSS 0.4%CVE-2023-2241MEDIUMPoDoFo PdfXRefStreamParserObject.cpp readXRefStreamEntry heap-based overflowEPSS 0.4%CVE-2026-55331HIGHIn IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code executiEPSS 0.4%CVE-2026-11516MEDIUMUTT HiPER 2610G formNatStaticMap strcpy buffer overflowEPSS 0.4%CVE-2022-25635MEDIUMRealtek Linux/Android Bluetooth Mesh SDK - Buffer OverflowEPSS 0.4%CVE-2024-28583HIGHBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the readLine()EPSS 0.4%CVE-2026-2920HIGHGStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-24823CRITICALA heap-based buffer over-read or buffer overflow vulnerability in FASTSHIFT/X-TRACKEPSS 0.4%CVE-2023-52377HIGHVulnerability of input data not being verified in the cellular data module.Successful exploitation of this vulnerability may cause out-of-boEPSS 0.4%