Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2022-33232CRITICALBuffer copy without checking size of input in HypervisorEPSS 0.1%CVE-2022-33276HIGHBuffer copy without checking size of input in ModemEPSS 0.1%CVE-2022-33224MEDIUMBuffer copy without checking the size of input in CoreEPSS 0.1%CVE-2022-25746HIGHBuffer Copy Without Checking Size of Input in KernelEPSS 0.1%CVE-2023-21639MEDIUMBuffer Copy Without Checking the Size of Input in AudioEPSS 0.1%CVE-2022-33230MEDIUMBuffer copy without checking the size of input in FM HostEPSS 0.1%CVE-2023-21649MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLANEPSS 0.1%CVE-2023-21640MEDIUMBuffer Copy Without Checking Size of Input in LinuxEPSS 0.1%CVE-2022-33226MEDIUMBuffer copy without checking the size of input in CoreEPSS 0.1%CVE-2023-21635MEDIUMBuffer Copy without Checking Size of Input in Data Network Stack & ConnectivityEPSS 0.1%CVE-2023-32859MEDIUMIn meta, there is a possible classic buffer overflow due to a missing bounds check. This could lead to local escalation of privilege with SyEPSS 0.1%CVE-2018-25281MEDIUMiCash 7.6.5 Denial of Service via Connect to ServerEPSS 0.1%CVE-2024-56450MEDIUMBuffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2023-24283LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of SEPSS 0.1%CVE-2025-0045MEDIUMImproper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potEPSS 0.1%CVE-2021-25467MEDIUMAssuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release EPSS 0.1%CVE-2025-47372CRITICALBuffer Copy Without Checking Size of Input in BootEPSS 0.1%CVE-2026-18321MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsecEPSS 0.1%CVE-2023-33023HIGHBuffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in SPS-ApplicationsEPSS 0.1%CVE-2023-33072CRITICALBuffer copy without checking size of Input in CoreEPSS 0.1%