Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-69209MEDIUMArduinoCore-avr has Stack-Based Buffer Overflow in WString Float/Double ConstructorsEPSS 0.2%CVE-2025-0303HIGHLiteos_a has a buffer overflow vulnerabilityEPSS 0.2%CVE-2022-49040MEDIUMBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functionality in Synology DrivEPSS 0.2%CVE-2022-49041MEDIUMBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functionality in Synology DriEPSS 0.2%CVE-2024-0213HIGH A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause EPSS 0.2%CVE-2026-42450HIGHOpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parserEPSS 0.2%CVE-2026-64705MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS EPSS 0.2%CVE-2019-25326MEDIUMipPulse 1.92 - 'Enter Key' Denial of ServiceEPSS 0.2%CVE-2026-65357HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOEPSS 0.2%CVE-2026-30006MEDIUMXnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.EPSS 0.2%CVE-2026-84489MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, EPSS 0.2%CVE-2026-57246HIGHFoxit PDF Editor/Reader Signature Buffer Overflow VulnerabilityEPSS 0.2%CVE-2018-25369MEDIUMVisual Ping 0.8.0.0 Buffer Overflow Denial of ServiceEPSS 0.2%CVE-2026-28841MEDIUMA buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memoEPSS 0.2%CVE-2026-0157MEDIUMIn RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosurEPSS 0.2%CVE-2025-1253MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.EPSS 0.2%CVE-2026-84577HIGHAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app maEPSS 0.2%CVE-2026-43681HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2026-55277HIGHIn checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could leadEPSS 0.2%CVE-2026-30981MEDIUMiccDEV has a heap-buffer-overflow read in CIccXmlArrayType<>EPSS 0.2%