Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-18321MEDIUMBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsecEPSS 0.1%CVE-2023-43540HIGHBuffer Copy Without Checking Size of Input in Bluetooth HOSTEPSS 0.1%CVE-2021-43614MEDIUMVariableEditSmm: Error checking of UEFI variables could cause buffer overflow, leading to code executionEPSS 0.1%CVE-2024-23378MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-33035HIGHBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2023-28539MEDIUMBuffer Copy Without Checking Size of Input in WLAN HostEPSS 0.1%CVE-2023-28546HIGHBuffer Copy Without Checking Size of Input in SPS ApplicationsEPSS 0.1%CVE-2026-34866MEDIUMOut-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confiEPSS 0.1%CVE-2023-33031HIGHBuffer Copy Without Checking Size of Input in Automotive AudioEPSS 0.1%CVE-2023-43515MEDIUMBuffer copy without checking size of input (Classic buffer overflow) in HLOSEPSS 0.1%CVE-2023-43526MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-43525MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2024-45541HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in WLAN Windows HostEPSS 0.1%CVE-2023-33069MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2024-49829MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in CameraEPSS 0.1%CVE-2023-33077MEDIUMBuffer Copy Without Checking Size of Input in HLOSEPSS 0.1%CVE-2023-43524MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%CVE-2023-33068MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2023-22384MEDIUMBuffer Copy Without Checking Size of Input in VR ServiceEPSS 0.1%CVE-2024-49830MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in AudioEPSS 0.1%