Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-42808MEDIUMAn issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11.  The host streaming API function {{coines_read_stream_seEPSS 0.3%CVE-2026-82343MEDIUMGimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handlingEPSS 0.3%CVE-2023-43519HIGHBuffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in VideoEPSS 0.3%CVE-2025-55499MEDIUMTenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.EPSS 0.3%CVE-2023-43548HIGHBuffer Copy Without Checking Size of Input in VideoEPSS 0.3%CVE-2025-21780HIGHdrm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()EPSS 0.3%CVE-2025-51824MEDIUMlibcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.EPSS 0.3%CVE-2018-9418HIGHIn handle_app_cur_val_response of dtif_rc.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to reEPSS 0.3%CVE-2024-48289MEDIUMAn issue in the Bluetooth Low Energy implementation of Cypress Bluetooth SDK v3.66 allows attackers to cause a Denial of Service (DoS) via sEPSS 0.3%CVE-2024-43700HIGHxfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow EPSS 0.3%CVE-2021-3569—A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could resulEPSS 0.3%CVE-2025-10889HIGHCATPART File Parsing Memory Corruption VulnerabilityEPSS 0.3%CVE-2023-27968HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.3%CVE-2024-35410MEDIUMwac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows attackersEPSS 0.3%CVE-2022-42261HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may leaEPSS 0.3%CVE-2024-48806MEDIUMBuffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a craftEPSS 0.3%CVE-2025-25453MEDIUMTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.EPSS 0.3%CVE-2025-25458MEDIUMTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.EPSS 0.3%CVE-2024-20313HIGHA vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause aEPSS 0.3%CVE-2024-30799MEDIUMAn issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach REPSS 0.3%