Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-10887HIGHMODEL File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2025-5038HIGHX_T File Parsing Memory Corruption VulnerabilityEPSS 0.2%CVE-2021-41216MEDIUMHeap buffer overflow in `Transpose`EPSS 0.2%CVE-2025-25523MEDIUMBuffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related tEPSS 0.2%CVE-2026-5164MEDIUMVirtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap requestEPSS 0.2%CVE-2023-33092HIGHBuffer Copy Without Checking Size of Input in Bluetooth HOSTEPSS 0.2%CVE-2020-8944MEDIUMUnchecked buffer overrun in ecall_restoreEPSS 0.2%CVE-2018-25301HIGHEasy MPEG to DVD Burner 1.7.11 SEH Local Buffer OverflowEPSS 0.2%CVE-2023-33087HIGHBuffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in CoreEPSS 0.2%CVE-2023-33017HIGHBuffer Copy Without Checking Size of Input in BootEPSS 0.2%CVE-2018-25302HIGHAllok AVI to DVD SVCD VCD Converter 4.0.1217 Buffer Overflow SEHEPSS 0.2%CVE-2023-28580MEDIUMBuffer Copy Without Checking Size of Input in WLAN HostEPSS 0.2%CVE-2025-53966HIGHAn issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, and 1580. Incorrect Handling of the NL80211 vendor command leadEPSS 0.2%CVE-2018-25264MEDIUMTransMac 12.2 Denial of Service via License Key FieldEPSS 0.2%CVE-2023-33024MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Radio Interface LayerEPSS 0.2%CVE-2025-49495HIGHAn issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580. Mishandling of an NL80211 vendor commaEPSS 0.2%CVE-2023-28579MEDIUMBuffer Copy Without Checking Size of Input in WLAN HostEPSS 0.2%CVE-2024-52064MEDIUMPotential stack buffer write overflow in Connext applications while parsing malicious license fileEPSS 0.2%CVE-2025-46776MEDIUMA buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiEEPSS 0.2%CVE-2024-52065MEDIUMPotential stack buffer write overflow in Persistence Service while parsing malicious environment variable on non-Windows systemsEPSS 0.2%