Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2020-37194MEDIUMBackup Key Recovery Recover Keys Crashed Hard Disk Drive 2.2.5 - 'Key' Denial of ServiceEPSS 0.3%CVE-2010-10017HIGHWM Downloader 3.1.2.2 Buffer Overflow via Malformed M3U FileEPSS 0.3%CVE-2024-41596HIGHBuffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrievalEPSS 0.3%CVE-2024-41588HIGHThe CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticatedEPSS 0.3%CVE-2024-27878MEDIUMA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to executeEPSS 0.3%CVE-2026-24793CRITICALA heap-based buffer over-read or buffer overflow vulnerability in azerothcore/azerothcore-wotlkEPSS 0.3%CVE-2021-1379MEDIUMCisco IP Phones Cisco Discovery Protocol and Link Layer Discovery Protocol Remote Code Execution and Denial of Service VulnerabilitiesEPSS 0.3%CVE-2025-57275MEDIUMStorage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf.EPSS 0.3%CVE-2025-52222HIGHD-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-80EPSS 0.3%CVE-2025-59947HIGHNanoMQ has Buffer OverflowEPSS 0.3%CVE-2025-65404MEDIUMA buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) EPSS 0.3%CVE-2024-45619MEDIUMLibopensc: incorrect handling length of buffers or files in libopenscEPSS 0.3%CVE-2024-51347HIGHA buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handling of the Time Zone EPSS 0.3%CVE-2025-65403MEDIUMA buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.EPSS 0.3%CVE-2025-11780HIGHStack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.3%CVE-2022-43752HIGHOracle Solaris version 10 1/13, when using the Common Desktop Environment (CDE), is vulnerable to a privilege escalation vulnerability. A loEPSS 0.3%CVE-2025-14911HIGHInteger Overflow in GridFS chunkSize Leading to Heap Allocation FailureEPSS 0.3%CVE-2023-28904MEDIUMBypass of secure boot processEPSS 0.3%CVE-2024-46657MEDIUMArtifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability alloEPSS 0.3%CVE-2020-24736MEDIUMBuffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted scriptEPSS 0.3%