Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2022-42756HIGHIn sensor driver, there is a possible buffer overflow due to a missing bounds check. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2026-19568HIGHSVG File Parsing Memory Corruption Vulnerability in Autodesk 3ds MaxEPSS 0.1%CVE-2021-25469MEDIUMA possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code execution.EPSS 0.1%CVE-2020-8937MEDIUMArbitrary enclave memory location write from untrusted environmentEPSS 0.1%CVE-2018-25285MEDIUMFathom 2.4 Denial of Service via Authorization Code Buffer OverflowEPSS 0.1%CVE-2025-24519MEDIUMBuffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of priEPSS 0.1%CVE-2018-25296MEDIUMP10 Central Management Software 1.4.13 Denial of ServiceEPSS 0.1%CVE-2018-25280MEDIUMInfiltrator Network Security Scanner 4.6 Denial of ServiceEPSS 0.1%CVE-2018-25287MEDIUMDrive Power Manager 1.10 Denial of Service via Name FieldEPSS 0.1%CVE-2026-20794CRITICALBuffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers mayEPSS 0.1%CVE-2026-20436MEDIUMIn wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilEPSS 0.1%CVE-2024-33054HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Computer VisionEPSS 0.1%CVE-2024-33052HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM HostEPSS 0.1%CVE-2024-33042HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in FM HostEPSS 0.1%CVE-2022-25712MEDIUMMemory corruption in camera due to buffer copy without checking size of input in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOEPSS 0.1%CVE-2018-25273MEDIUMCrossFont 7.5 Denial of Service via License Key FieldEPSS 0.1%CVE-2026-49895LOWIn get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This couEPSS 0.1%CVE-2026-58553MEDIUMOut-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2024-43055HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Camera_LinuxEPSS 0.1%CVE-2026-58549MEDIUMOut-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%