Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2020-37180MEDIUMGTalk Password Finder 2.2.1 - 'Key' Denial of ServiceEPSS 0.3%CVE-2024-26927HIGHASoC: SOF: Add some bounds checking to firmware dataEPSS 0.3%CVE-2020-37191MEDIUMTop Password Software Dialup Password Recovery 1.30 - Denial of ServiceEPSS 0.3%CVE-2020-37190MEDIUMTop Password Firefox Password Recovery 2.8 - Denial of ServiceEPSS 0.3%CVE-2024-6198HIGHSNORE Interface Unauthenticated Remote Code ExecutionEPSS 0.3%CVE-2020-37210MEDIUMSpotIE 2.9.5 - 'Key' Denial of ServiceEPSS 0.3%CVE-2020-37211MEDIUMSpotIM 2.2 - 'Name' Denial Of ServiceEPSS 0.3%CVE-2020-37212MEDIUMSpotMSN 2.4.6 - 'Name' Denial of ServiceEPSS 0.3%CVE-2024-21463HIGHBuffer Copy Without Checking Size of Input in AudioEPSS 0.3%CVE-2024-21480HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.3%CVE-2026-73774HIGHUnauthenticated Buffer Overflow Vulnerability leads to Sensitive Information Disclosure in AOS-CXEPSS 0.3%CVE-2023-6238MEDIUMKernel: nvme: memory corruption via unprivileged user passthroughEPSS 0.3%CVE-2025-27835HIGHAn issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.EPSS 0.3%CVE-2024-53426MEDIUMA heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.EPSS 0.3%CVE-2026-73772MEDIUMUnauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-CXEPSS 0.3%CVE-2024-52066HIGHPotential stack corruption in Routing Service when using a malicious XML configuration documentEPSS 0.3%CVE-2021-29612LOWHeap buffer overflow in `BandedTriangularSolve`EPSS 0.3%CVE-2025-8177MEDIUMLibTIFF thumbnail.c setrow buffer overflowEPSS 0.3%CVE-2026-22627HIGHA buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 maEPSS 0.3%CVE-2024-25196LOWOpen Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controllEPSS 0.3%