Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-52863LOWQTS, QuTS heroEPSS 0.4%CVE-2025-52864LOWQTS, QuTS heroEPSS 0.4%CVE-2025-40815HIGHA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versionEPSS 0.4%CVE-2025-29632MEDIUMBuffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handlEPSS 0.4%CVE-2022-47657HIGHGPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function hevc_parse_vps_extension of media_tools/av_parsers.c:7662EPSS 0.4%CVE-2022-47663HIGHGPAC MP4box 2.1-DEV-rev649-ga8f438d20 is vulnerable to buffer overflow in h263dmx_process filters/reframe_h263.c:609EPSS 0.4%CVE-2024-32230HIGHFFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture EPSS 0.4%CVE-2023-26733HIGHBuffer Overflow vulnerability found in tinyTIFF v.3.0 allows a local attacker to cause a denial of service via the TinyTiffReader_readNextFrEPSS 0.4%CVE-2025-25474MEDIUMDCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.EPSS 0.4%CVE-2022-25687HIGHmemory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, SEPSS 0.4%CVE-2026-92006HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.4%CVE-2024-44866MEDIUMA buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a DeniaEPSS 0.3%CVE-2025-1587MEDIUMSourceCodester Telecom Billing Management System Add New Record main.cpp addrecords buffer overflowEPSS 0.3%CVE-2020-37065HIGHStreamRipper32 2.6 - Buffer OverflowEPSS 0.3%CVE-2025-5037HIGHRFA File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2025-1372MEDIUMGNU elfutils eu-readelf readelf.c print_string_section buffer overflowEPSS 0.3%CVE-2022-40284HIGHA buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker cEPSS 0.3%CVE-2024-57184MEDIUMAn issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_process_pmt in media_EPSS 0.3%CVE-2025-53474HIGHBIG-IP iRules vulnerabilityEPSS 0.3%CVE-2025-4891MEDIUMcode-projects Police Station Management System Display Record source.cpp display buffer overflowEPSS 0.3%