Fallos del tipo CWE-120

3168 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-44951HIGHA missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a locEPSS 0.2%CVE-2021-29520LOWHeap buffer overflow in `Conv3DBackprop*`EPSS 0.2%CVE-2026-20449MEDIUMIn Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connectedEPSS 0.2%CVE-2023-27957HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously craEPSS 0.2%CVE-2023-38581HIGHBuffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation EPSS 0.2%CVE-2024-6564MEDIUMBuffer overflow in Rensas RCAREPSS 0.2%CVE-2025-27833HIGHAn issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.EPSS 0.2%CVE-2023-29932MEDIUMllvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.EPSS 0.2%CVE-2023-37926MEDIUMA buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through EPSS 0.2%CVE-2021-41221HIGHAccess to invalid memory during shape inference in `Cudnn*` opsEPSS 0.2%CVE-2023-28736MEDIUMBuffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalatioEPSS 0.2%CVE-2025-57573MEDIUMTenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi.EPSS 0.2%CVE-2025-57572MEDIUMTenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentControl.EPSS 0.2%CVE-2022-50687MEDIUMCobian Backup 11 Gravity 11.2.0.582 Local Denial of Service via Password FieldEPSS 0.2%CVE-2025-1660HIGHDWFX File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2022-44455MEDIUMThe appspawn and nwebspawn services were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.EPSS 0.2%CVE-2026-76699MEDIUMUnauthenticated Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.2%CVE-2022-27242—A vulnerability has been identified in OpenV2G (V0.9.4). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial EPSS 0.2%CVE-2021-22547MEDIUMBuffer overrun in Google Cloud IoT Device SDK for Embedded CEPSS 0.2%CVE-2024-50090HIGHdrm/xe/oa: Fix overflow in oa batch bufferEPSS 0.2%