Fallos del tipo CWE-120

3168 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-0849LOWcrypto: ATAES132A response length allows stack buffer overflowEPSS 0.2%CVE-2025-3148MEDIUMcodeprojects Product Management System Login buffer overflowEPSS 0.2%CVE-2020-37215MEDIUMMSN Password Recovery 1.30 - Denial of ServiceEPSS 0.2%CVE-2025-29481MEDIUMBuffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of lEPSS 0.2%CVE-2020-8905LOWConfidential Information Disclosure vulnerability in AsyloEPSS 0.2%CVE-2023-23535MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11EPSS 0.2%CVE-2026-20608MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iEPSS 0.2%CVE-2025-29482MEDIUMBuffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) proceEPSS 0.2%CVE-2023-27955MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Monterey 12.6.4, tvEPSS 0.2%CVE-2023-20168HIGHA vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to causeEPSS 0.2%CVE-2022-3077—A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it handled the I2C_SMBUS_EPSS 0.2%CVE-2020-37164MEDIUMAbsoluteTelnet 11.12 - "license entry" Denial of ServiceEPSS 0.2%CVE-2023-30083MEDIUMBuffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the newVar_N in utiEPSS 0.2%CVE-2021-33897MEDIUMA buffer overflow in Synthesia before 10.7.5567, when a non-Latin locale is used, allows user-assisted attackers to cause a denial of servicEPSS 0.2%CVE-2020-37165MEDIUMAbsoluteTelnet 11.12 - "license name" Denial of ServiceEPSS 0.2%CVE-2023-30085MEDIUMBuffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the cws2fws functioEPSS 0.2%CVE-2025-46714HIGHSandboxie has Pool Buffer Overflow in SbieDrv.sys API (API_GET_SECURE_PARAM)EPSS 0.2%CVE-2023-24809MEDIUMNetHack Call command buffer overflowEPSS 0.2%CVE-2022-21742MEDIUMRealtek USB FE/1GbE/2.5GbE/5GbE NIC Family - Buffer OverflowEPSS 0.2%CVE-2024-55045HIGHFirmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_EPSS 0.2%