Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-1679HIGHnet: eswifi socket send payload length not boundedEPSS 0.2%CVE-2025-69674MEDIUMBuffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute arbitrary code via theEPSS 0.2%CVE-2021-29540LOWHeap buffer overflow in `Conv2DBackpropFilter`EPSS 0.2%CVE-2024-40674MEDIUMIn validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the cEPSS 0.2%CVE-2024-0099HIGHCVEEPSS 0.2%CVE-2023-25505HIGHNVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler of the AMI MegaRAC BMC , where an attacker with the appropriate level of authoEPSS 0.2%CVE-2024-29166MEDIUMHDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing deniEPSS 0.2%CVE-2026-0141MEDIUMIn decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information dEPSS 0.2%CVE-2020-37042HIGHFrigate Professional 3.36.0.9 - 'Find Computer' Local Buffer OverflowEPSS 0.2%CVE-2022-49754HIGHBluetooth: Fix a buffer overflow in mgmt_mesh_add()EPSS 0.2%CVE-2024-6563HIGHBuffer Overflow Arbitrary WriteEPSS 0.2%CVE-2021-36333MEDIUMDell EMC CloudLink 7.1 and all prior versions contain a Buffer Overflow Vulnerability. A local low privileged attacker, may potentially explEPSS 0.2%CVE-2021-29512LOWHeap buffer overflow in `RaggedBinCount`EPSS 0.2%CVE-2022-50689MEDIUMCobian Reflector 0.9.93 RC1 Local Denial of Service via Password FieldEPSS 0.2%CVE-2020-37040HIGHCode Blocks 17.12 - 'File Name' Local Buffer OverflowEPSS 0.2%CVE-2022-47990MEDIUMIBM AIX denial of serviceEPSS 0.2%CVE-2023-6948LOWA Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 coulEPSS 0.2%CVE-2022-42283MEDIUMNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service EPSS 0.2%CVE-2025-12142MEDIUMBSS(Block Started by Symbol) Memory Corruption VulnerabilityEPSS 0.2%CVE-2026-68768MEDIUMhashcat through 7.1.2 Heap Buffer Overflow in outfile_write() via Oversized UsernameEPSS 0.2%