Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-6688HIGHFatFs Buffer Overflow via Unbounded LFN Filename CopyEPSS 0.3%CVE-2020-37209MEDIUMSpotFTP FTP Password Recovery 3.0.0.0 - 'Name' Denial of ServiceEPSS 0.3%CVE-2024-25580MEDIUMAn issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x befEPSS 0.3%CVE-2023-51793HIGHBuffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.cEPSS 0.3%CVE-2022-29974MEDIUMAMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is, for example, used EPSS 0.3%CVE-2023-3164MEDIUMHeap-buffer-overflow in extractimagesection()EPSS 0.3%CVE-2025-49458MEDIUMZoom Workplace Clients - Buffer OverflowEPSS 0.3%CVE-2024-45620LOWLibopensc: incorrect handling of the length of buffers or files in pkcs15initEPSS 0.3%CVE-2023-51798HIGHBuffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exceptiEPSS 0.3%CVE-2022-47658HIGHGPAC MP4Box 2.1-DEV-rev644-g5c4df2a67 is vulnerable to buffer overflow in function gf_hevc_read_vps_bs_internal of media_tools/av_parsers.c:EPSS 0.3%CVE-2020-37195MEDIUMBlueAuditor 1.7.2.0 - 'Name' Denial of ServiceEPSS 0.3%CVE-2024-46952HIGHAn issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stEPSS 0.3%CVE-2022-47654HIGHGPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:EPSS 0.3%CVE-2026-12192HIGHGALAYOU Y4 Web Server buffer overflowEPSS 0.3%CVE-2020-37185MEDIUMBackup Key Recovery 2.2.5 - 'Name' Denial of ServiceEPSS 0.3%CVE-2022-47656HIGHGPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:EPSS 0.3%CVE-2020-37179MEDIUMAPKF Product Key Finder 2.5.8.0 - 'Name' Denial of ServiceEPSS 0.3%CVE-2025-65102HIGHPJSIP is vulnerable to buffer overflow in Opus PLCEPSS 0.3%CVE-2026-24810CRITICALA buffer overflow in rethinkdb/rethinkdbEPSS 0.3%CVE-2023-27590HIGHRizin has stack-based buffer overflow when parsing GDB registers profile filesEPSS 0.3%