Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-43312MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.EPSS 0.3%CVE-2024-20313HIGHA vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause aEPSS 0.3%CVE-2026-92043HIGHPrivilege escalation due to incorrect boundary conditions in the Audio/Video componentEPSS 0.3%CVE-2026-92014HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics componentEPSS 0.3%CVE-2024-32324HIGHBuffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to execute arbitrary code EPSS 0.3%CVE-2022-42271HIGHNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service EPSS 0.3%CVE-2024-58109MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-58108MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-58110MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2022-42274HIGHNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service EPSS 0.3%CVE-2022-47090HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check EPSS 0.3%CVE-2024-58106MEDIUMBuffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.3%CVE-2024-35422HIGHvmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c.EPSS 0.3%CVE-2024-31963MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.3%CVE-2024-56557HIGHiio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xferEPSS 0.3%CVE-2024-12194HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.3%CVE-2026-18280LOWSony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution VulnerabilityEPSS 0.3%CVE-2023-52364MEDIUMVulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may EPSS 0.3%CVE-2024-53335HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.EPSS 0.3%CVE-2024-28759MEDIUMA crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.EPSS 0.2%