Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-64747HIGHA buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26EPSS 0.2%CVE-2026-43776HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26EPSS 0.2%CVE-2026-7454HIGHWRL File Parsing Memory Corruption in Autodesk 3ds MaxEPSS 0.2%CVE-2025-23236HIGHBuffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operationEPSS 0.2%CVE-2024-0146HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory corruption. A successfuEPSS 0.2%CVE-2026-7452HIGHWRL File Parsing Memory Corruption in Autodesk 3ds MaxEPSS 0.2%CVE-2025-48611CRITICALIn DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation oEPSS 0.2%CVE-2026-30979HIGHiccDEV has a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp()EPSS 0.2%CVE-2022-3742MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%CVE-2026-52489HIGHBuffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameTEPSS 0.2%CVE-2020-36994MEDIUMQlikView 12.50.20000.0 - 'FTP Server Address' Denial of ServiceEPSS 0.2%CVE-2024-57509HIGHBuffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary codeEPSS 0.2%CVE-2022-41802MEDIUMKernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres.EPSS 0.2%CVE-2021-26409HIGHInsufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resulting in a loss of SEPSS 0.2%CVE-2026-36189MEDIUMBuffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e67b9a1435a1bb173b106EPSS 0.2%CVE-2025-9558HIGHBluetooth: Mesh: Out-of-Bound Write in gen_prov_startEPSS 0.2%CVE-2024-57510HIGHBuffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary codeEPSS 0.2%CVE-2026-84497HIGHA buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS EPSS 0.2%CVE-2024-37816MEDIUMQuectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.EPSS 0.2%CVE-2026-6691HIGHMongoDB C Driver Cyrus SASL Canonicalization Buffer OverflowEPSS 0.2%