Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-4891MEDIUMcode-projects Police Station Management System Display Record source.cpp display buffer overflowEPSS 0.3%CVE-2025-45866MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interfaceEPSS 0.3%CVE-2025-4889MEDIUMcode-projects Tourism Management System User Registration AddUser buffer overflowEPSS 0.3%CVE-2024-44232MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS SeEPSS 0.3%CVE-2024-44233MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS SeEPSS 0.3%CVE-2024-40427HIGHStack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the progrEPSS 0.3%CVE-2020-37203MEDIUMOffice Product Key Finder 1.5.4 - Denial of ServiceEPSS 0.3%CVE-2024-44234MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS SeEPSS 0.3%CVE-2020-37202MEDIUMNetworkSleuth 3.0.0.0 - 'Key' Denial of ServiceEPSS 0.3%CVE-2025-1365MEDIUMGNU elfutils eu-readelf readelf.c process_symtab buffer overflowEPSS 0.3%CVE-2023-25435MEDIUMlibtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753.EPSS 0.3%CVE-2025-43370MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may craEPSS 0.3%CVE-2025-55297MEDIUMESF-IDF BluFi Example Memory Overflow VulnerabilityEPSS 0.3%CVE-2024-24972MEDIUMBuffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authoriseEPSS 0.3%CVE-2022-47091HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.cEPSS 0.3%CVE-2011-10025HIGHSubtitle Processor 7.7.1 .m3u SEH Unicode Buffer OverflowEPSS 0.3%CVE-2024-28569HIGHBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::XEPSS 0.3%CVE-2026-3081HIGHGStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-88775HIGHMemory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of ServiceEPSS 0.3%CVE-2021-34987HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An attacker EPSS 0.3%