Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-90803MEDIUMGNU Binutils ld elf64-x86-64.c elf_x86_64_relocate_section buffer overflowEPSS 0.2%CVE-2026-71613HIGHBuffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_pEPSS 0.2%CVE-2022-1110MEDIUMA buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of serEPSS 0.2%CVE-2022-0636MEDIUMA denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.EPSS 0.2%CVE-2025-6634HIGHTGA File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2023-52080HIGHIEIT NF5280M6 UEFI firmware through 8.4 has a pool overflow vulnerability, caused by improper use of the gRT->GetVariable() function. AttackEPSS 0.2%CVE-2026-30987HIGHiccDEV has a stack buffer overflow in CIccTagNum<(icTagTypeSignature)>::GetValues()EPSS 0.2%CVE-2026-30985HIGHiccDEV has a heap-based buffer overflow write in CIccMatrixMath::SetRange()EPSS 0.2%CVE-2026-30983HIGHiccDEV has a stack buffer overflow in icFixXml()EPSS 0.2%CVE-2026-31795HIGHiccDEV has a stack buffer overflow write in CIccXform3DLut::Apply()EPSS 0.2%CVE-2022-48696HIGHregmap: spi: Reserve space for register address/paddingEPSS 0.2%CVE-2024-54105MEDIUMRead/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.2%CVE-2026-90804LOWGNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overflowEPSS 0.2%CVE-2023-47217MEDIUMArkruntime has a buffer overflow vulnerabilityEPSS 0.2%CVE-2026-28981HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2023-4029MEDIUMA buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with locEPSS 0.2%CVE-2023-34419MEDIUMA buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local accEPSS 0.2%CVE-2023-4028MEDIUMA buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker wEPSS 0.2%CVE-2026-64747HIGHA buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26EPSS 0.2%CVE-2026-43776HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26EPSS 0.2%