Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-44560CRITICALowntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.EPSS 0.3%CVE-2025-5828MEDIUMAutel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-52063HIGHPotential stack buffer write overflow in Connext applications while parsing malicious XML types documentEPSS 0.3%CVE-2013-1424MEDIUMBuffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787.EPSS 0.3%CVE-2017-13319HIGHIn pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lEPSS 0.3%CVE-2026-71399HIGHAdobe XD | Buffer Overflow (CWE-120)EPSS 0.3%CVE-2023-52549HIGHVulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.3%CVE-2023-52550HIGHVulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.3%CVE-2025-3728MEDIUMSourceCodester Simple Hotel Booking System login buffer overflowEPSS 0.3%CVE-2026-31280MEDIUMAn issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause a Denial of ServiceEPSS 0.3%CVE-2024-57577MEDIUMTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.EPSS 0.3%CVE-2024-22919HIGHswftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.EPSS 0.3%CVE-2024-39543HIGHJunos OS and Junos OS Evolved: Receipt of a large RPKI-RTR PDU packet can cause rpd to crashEPSS 0.3%CVE-2024-39538HIGHJunos OS Evolved: ACX7000 Series: When multicast traffic with a specific (S,G) is received evo-pfemand crashesEPSS 0.3%CVE-2025-7677HIGHDOS attack possibleEPSS 0.3%CVE-2019-25354MEDIUMiSmartViewPro 1.3.34 - Denial of ServiceEPSS 0.3%CVE-2025-52960HIGHJunos OS: SRX Series and MX Series: Receipt of specific SIP packets in a high utilization situation causes a flowd/mspmand crashEPSS 0.3%CVE-2021-0115MEDIUMBuffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via lEPSS 0.3%CVE-2020-37175MEDIUMP2PWIFICAM2 for iOS 10.4.1 - 'Camera ID' Denial of ServiceEPSS 0.3%CVE-2020-37194MEDIUMBackup Key Recovery Recover Keys Crashed Hard Disk Drive 2.2.5 - 'Key' Denial of ServiceEPSS 0.3%