Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2022-42760MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2025-20149MEDIUMA vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affectedEPSS 0.1%CVE-2022-33217HIGHMemory corruption in Qualcomm IPC due to buffer copy without checking the size of input while starting communication with a compromised kernEPSS 0.1%CVE-2023-33113HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in KernelEPSS 0.1%CVE-2025-32732MEDIUMBuffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service.EPSS 0.1%CVE-2023-52551MEDIUMVulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.1%CVE-2018-25305MEDIUMlibrsvg2-bin 2.40.13 Buffer Overflow via Malformed SVGEPSS 0.1%CVE-2023-33085HIGHBuffer Copy Without Checking Size of Input (Classic Buffer Overflow) in WearablesEPSS 0.1%CVE-2022-33288CRITICALBuffer copy without checking the size of input in CoreEPSS 0.1%CVE-2018-25297MEDIUMWansview 1.0.2 Denial of Service via Buffer OverflowEPSS 0.1%CVE-2022-23431MEDIUMAn improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.EPSS 0.1%CVE-2022-39118MEDIUMIn sprd_sysdump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service inEPSS 0.1%CVE-2023-28544HIGHBuffer Copy without Checking the Size of Input in WLAN FirmwareEPSS 0.1%CVE-2023-28560HIGHBuffer Copy Without Checking Size of Input in WLAN HALEPSS 0.1%CVE-2022-33232CRITICALBuffer copy without checking size of input in HypervisorEPSS 0.1%CVE-2018-25276MEDIUMRoboImport 1.2.0.72 Denial of Service via Registration FieldsEPSS 0.1%CVE-2023-24851HIGHBuffer Copy Without Checking Size of Input in WLAN HOSTEPSS 0.1%CVE-2023-21664HIGHBuffer Copy without Checking the Size of Input(Classic Buffer Overflow) in Core PlatformEPSS 0.1%CVE-2023-21662HIGHBuffer Copy without Checking the Size of Input(Classic Buffer Overflow) in Core PlatformEPSS 0.1%CVE-2022-33276HIGHBuffer copy without checking size of input in ModemEPSS 0.1%