Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-26797HIGHdrm/amd/display: Prevent potential buffer overflow in map_hw_resourcesEPSS 0.2%CVE-2026-1109MEDIUMcijliu librtsp rtsp_parse_request buffer overflowEPSS 0.2%CVE-2024-28759MEDIUMA crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.EPSS 0.2%CVE-2025-33130MEDIUMFixes to common vulnerabilities found in IBM Db2 Merge Backup for Linux, UNIX and WindowsEPSS 0.2%CVE-2025-25526MEDIUMBuffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration EPSS 0.2%CVE-2025-25527MEDIUMBuffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the confiEPSS 0.2%CVE-2025-55495MEDIUMTenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.EPSS 0.2%CVE-2020-37213MEDIUMTextCrawler Pro3.1.1 - Denial of ServiceEPSS 0.2%CVE-2024-30165HIGHAmazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands wEPSS 0.2%CVE-2025-25525MEDIUMBuffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which is related to the sEPSS 0.2%CVE-2025-25529MEDIUMBuffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is related to the configEPSS 0.2%CVE-2019-25353MEDIUMFoscam Video Management System 1.1.4.9 - 'Username' Denial of ServiceEPSS 0.2%CVE-2019-25349MEDIUMscadaApp for iOS 1.1.4.0 - 'Servername' Denial of ServiceEPSS 0.2%CVE-2023-51796LOWBuffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reversEPSS 0.2%CVE-2024-32228MEDIUMFFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.EPSS 0.2%CVE-2024-8882MEDIUMA buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow anEPSS 0.2%CVE-2025-65226MEDIUMTenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.EPSS 0.2%CVE-2025-3139MEDIUMcode-projects Bus Reservation System Login Form login buffer overflowEPSS 0.2%CVE-2023-32356HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28213HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%