Fallos del tipo CWE-120

3168 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2023-32401HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.6.6, macOS Big Sur 11.7.7, macOS VenEPSS 0.2%CVE-2022-4969MEDIUMbwoodsend rockhopper Binary Parser ragged_array.c count_rows buffer overflowEPSS 0.2%CVE-2023-4397MEDIUMA buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, USG FLEX 50(W) series EPSS 0.2%CVE-2024-3506HIGHCamera Driver possible Buffer OverflowEPSS 0.2%CVE-2024-48426MEDIUMA segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSEPSS 0.2%CVE-2024-54568MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may leaEPSS 0.2%CVE-2025-1430HIGHSLDPRT File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2026-0164HIGHIn Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additionalEPSS 0.2%CVE-2026-0154HIGHIn Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This could lead to remote coEPSS 0.2%CVE-2026-0160HIGHIn TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds cEPSS 0.2%CVE-2025-46713HIGHSandboxie has Pool Buffer Overflow in SbieDrv.sys API (API_SET_SECURE_PARAM)EPSS 0.2%CVE-2024-31007MEDIUMBuffer Overflow vulnerability in IrfanView 32bit v.4.66 allows a local attacker to cause a denial of service via a crafted file. Affected coEPSS 0.2%CVE-2023-43567MEDIUMA buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevEPSS 0.2%CVE-2023-43576MEDIUMA buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privilegEPSS 0.2%CVE-2023-43577MEDIUMA buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privilegeEPSS 0.2%CVE-2023-43571MEDIUMA buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevatEPSS 0.2%CVE-2025-29480MEDIUMBuffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release functEPSS 0.2%CVE-2023-43573MEDIUMA buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attackerEPSS 0.2%CVE-2023-43580MEDIUMA buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privEPSS 0.2%CVE-2023-43569MEDIUMA buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privilegesEPSS 0.2%