Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-4497MEDIUMcode-projects Simple Banking System Sign In buffer overflowEPSS 0.4%CVE-2023-33302MEDIUMA buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface versionEPSS 0.4%CVE-2024-20723HIGHAdobe Substance 3D Painter v9.0.1Build2822 Buffer Overflow VulnerabilityEPSS 0.4%CVE-2026-5279HIGHObject corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2024-1755HIGHNPS computy <= 2.7.5 - Results Deletion via CSRFEPSS 0.4%CVE-2025-25723HIGHBuffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.EPSS 0.4%CVE-2025-25472MEDIUMA buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM file.EPSS 0.4%CVE-2024-44415MEDIUMA vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed EPSS 0.4%CVE-2025-1367MEDIUMMicroWord eScan Antivirus USB Password sprintf buffer overflowEPSS 0.4%CVE-2024-12354MEDIUMSourceCodester Phone Contact Manager System User Menu MenuDisplayStart buffer overflowEPSS 0.4%CVE-2024-37571MEDIUMBuffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensitive information via cEPSS 0.4%CVE-2023-30257HIGHA buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privileges to root.EPSS 0.4%CVE-2020-37074HIGHRemote Desktop Audit 2.3.0.157 - Buffer Overflow (SEH)EPSS 0.4%CVE-2020-37201MEDIUMNetShareWatcher 1.5.8.0 - 'Name' Denial Of ServiceEPSS 0.4%CVE-2024-22912HIGHA global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5compiler.flex:327. It allows an attacker to cause coEPSS 0.4%CVE-2022-46456HIGHNASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c.EPSS 0.4%CVE-2024-45237CRITICALAn issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync oEPSS 0.4%CVE-2024-48981HIGHAn issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet heEPSS 0.4%CVE-2022-40261HIGHSMM memory corruption vulnerability in OverClockSmiHandler SMM driverEPSS 0.4%CVE-2025-52863LOWQTS, QuTS heroEPSS 0.4%