Fallos del tipo CWE-120

3167 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-24153MEDIUMA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges EPSS 0.2%CVE-2023-28209HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28213HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28210HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28212HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28211HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-28215HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2023-32356HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause EPSS 0.2%CVE-2024-6352MEDIUMMalformed packet leads to denial of service in APS layerEPSS 0.2%CVE-2020-37170MEDIUMTapinRadio 2.12.3 - 'address' Denial of ServiceEPSS 0.2%CVE-2024-6351MEDIUMMalformed packet leads to denial of service in NWK/APS layerEPSS 0.2%CVE-2024-53192HIGHclk: clk-loongson2: Fix potential buffer overflow in flexible-array member accessEPSS 0.2%CVE-2025-64182MEDIUMOpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()EPSS 0.2%CVE-2020-37171MEDIUMTapinRadio 2.12.3 - 'username' Denial of ServiceEPSS 0.2%CVE-2020-37131MEDIUMProduct Key Explorer 4.2.2.0 - 'Key' Denial of ServiceEPSS 0.2%CVE-2023-27956MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iEPSS 0.2%CVE-2024-48425MEDIUMA segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library duriEPSS 0.2%CVE-2024-29645HIGHBuffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.EPSS 0.2%CVE-2025-29476MEDIUMBuffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2 v.2.17.0EPSS 0.2%CVE-2025-37803HIGHudmabuf: fix a buf size overflow issue during udmabuf creationEPSS 0.2%