Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2022-23817HIGHInsufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application toEPSS 0.2%CVE-2026-6691HIGHMongoDB C Driver Cyrus SASL Canonicalization Buffer OverflowEPSS 0.2%CVE-2025-29338MEDIUMNXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buffer overflow via the EPSS 0.2%CVE-2023-29414HIGH A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalaEPSS 0.2%CVE-2024-25724HIGHIn RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, QueuEPSS 0.2%CVE-2020-37029HIGHFTPDummy 4.80 - Local Buffer OverflowEPSS 0.2%CVE-2018-25376HIGHSocusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEHEPSS 0.2%CVE-2020-37024HIGHNidesoft DVD Ripper 5.2.18 - Local Buffer OverflowEPSS 0.2%CVE-2020-37028HIGHSocusoft Photo to Video Converter Professional 8.07 - 'Output Folder' Buffer OverflowEPSS 0.2%CVE-2018-25366HIGHCuteFTP 5.0 XP Buffer Overflow via Site Manager Label FieldEPSS 0.2%CVE-2020-37025HIGHPort Forwarding Wizard 4.8.0 - Buffer OverflowEPSS 0.2%CVE-2023-50821MEDIUMA vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC04), SIMATIC WinCC Runtime Professional V17 (All versioEPSS 0.2%CVE-2024-45184MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 210EPSS 0.2%CVE-2021-37650HIGHSegfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord` in TensorFlowEPSS 0.2%CVE-2018-25377HIGHFlash Slideshow Maker Professional 5.20 Buffer Overflow SEHEPSS 0.2%CVE-2018-25284MEDIUMHD Tune Pro 5.70 Denial of Service via Options DialogEPSS 0.2%CVE-2024-44306HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to executeEPSS 0.2%CVE-2024-44307HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to executeEPSS 0.2%CVE-2022-43662MEDIUMKernel subsystem in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime.EPSS 0.2%CVE-2025-27071HIGHBuffer Copy Without Checking Size of Input in Powerline Communication FirmwareEPSS 0.2%