Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2022-47088HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow.EPSS 0.3%CVE-2022-47087HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b has a Buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.cEPSS 0.3%CVE-2024-52060HIGHPotential stack overflow when using XML configuration file referencing environment variablesEPSS 0.3%CVE-2022-47089HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.cEPSS 0.3%CVE-2024-57513MEDIUMA floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.EPSS 0.3%CVE-2022-47653HIGHGPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113EPSS 0.3%CVE-2026-24184HIGHNVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attackeEPSS 0.3%CVE-2021-33983HIGHBuffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc execution of the erEPSS 0.3%CVE-2024-52026MEDIUMNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameteEPSS 0.3%CVE-2024-50994MEDIUMNetgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipEPSS 0.3%CVE-2024-52029MEDIUMNetgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at genie_pptp.cgi. This vulnerabiliEPSS 0.3%CVE-2024-52025MEDIUMNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameteEPSS 0.3%CVE-2024-52023MEDIUMNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameteEPSS 0.3%CVE-2026-84126MEDIUMIncorrect boundary conditions in the Layout: Grid componentEPSS 0.3%CVE-2025-5601HIGHBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') in WiresharkEPSS 0.3%CVE-2022-42431HIGHThis vulnerability allows local attackers to escalate privileges on affected Tesla vehicles. An attacker must first obtain the ability to exEPSS 0.3%CVE-2024-52028MEDIUMNetgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at wiz_pptp.cgi. This vulnerabilityEPSS 0.3%CVE-2022-47664HIGHLibde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sseEPSS 0.3%CVE-2024-51002MEDIUMNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tEPSS 0.3%CVE-2024-52024MEDIUMNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameteEPSS 0.3%