Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-56455MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%CVE-2024-56453MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%CVE-2024-56454MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%CVE-2026-0056LOWIn setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local informationEPSS 0.1%CVE-2024-56456MEDIUMVulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of thEPSS 0.1%CVE-2026-24076MEDIUMBuffer Copy Without Checking Size of Input in Bluetooth HOSTEPSS 0.1%CVE-2023-21136—In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could leaEPSS 0.1%CVE-2025-21443HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Automotive Vehicle NetworksEPSS 0.1%CVE-2024-48519MEDIUMBuffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denialEPSS 0.1%CVE-2026-16726MEDIUMBuffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.EPSS 0.1%CVE-2023-43538CRITICALBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in TZ Secure OSEPSS 0.1%CVE-2023-43556CRITICALBuffer Copy Without Checking Size of Input in HypervisorEPSS 0.1%CVE-2024-23368HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Qualcomm IPCEPSS 0.1%CVE-2023-24286LOWPortable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.EPSS 0.1%CVE-2025-47399HIGHBuffer Copy Without Checking Size of Input in CameraEPSS 0.1%CVE-2026-24080HIGHBuffer Copy Without Checking Size of Input in BiometricsEPSS 0.1%CVE-2018-9387HIGHIn multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This could lead to local eEPSS 0.1%CVE-2024-38423HIGHBuffer Copy Without Checking Size of Input in Graphics LinuxEPSS 0.1%CVE-2023-43542HIGHBuffer Copy Without Checking Size of Input in Trusted Execution EnvironmentEPSS 0.1%CVE-2024-38409HIGHBuffer Copy Without Checking Size of Input in WLAN Windows HostEPSS 0.1%