Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-44175MEDIUMTenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.EPSS 0.3%CVE-2023-42757MEDIUMProcess Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executaEPSS 0.3%CVE-2025-9390MEDIUMvim xxd xxd.c main buffer overflowEPSS 0.3%CVE-2024-30164MEDIUMAmazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissioEPSS 0.3%CVE-2024-26889MEDIUMBluetooth: hci_core: Fix possible buffer overflowEPSS 0.3%CVE-2025-1277HIGHPDF File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2024-50956MEDIUMA buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN 41.38.0.0, and HCPLCEPSS 0.3%CVE-2023-52365HIGHOut-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features tEPSS 0.3%CVE-2023-4163MEDIUMPossible buffer overflow in portcfgfportbuffers in Brocade Fabric OSEPSS 0.3%CVE-2024-53589HIGHGNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.EPSS 0.3%CVE-2025-25610HIGHTOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation EPSS 0.3%CVE-2026-0136HIGHIn Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2024-6350MEDIUMEmberZNet malformed MAC layer packet leads to denial of serviceEPSS 0.3%CVE-2026-0144HIGHIn writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote deEPSS 0.3%CVE-2025-25609HIGHTOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation EPSS 0.3%CVE-2026-3870MEDIUMA buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could EPSS 0.3%CVE-2024-25817HIGHBuffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, aEPSS 0.3%CVE-2026-3871MEDIUMA buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 couEPSS 0.3%CVE-2025-51823MEDIUMlibcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parameter. The function usEPSS 0.3%CVE-2026-42808MEDIUMAn issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11.  The host streaming API function {{coines_read_stream_seEPSS 0.3%