Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-33030MEDIUMBuffer Copy without Checking Size of Input (`Classic Buffer Overflow`) in PerformanceEPSS 0.1%CVE-2026-55285HIGHIn openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escEPSS 0.1%CVE-2026-56978HIGHIn get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalEPSS 0.1%CVE-2026-55301HIGHIn Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation oEPSS 0.1%CVE-2025-29944MEDIUMA buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resultingEPSS 0.1%CVE-2026-20782MEDIUMBuffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial oEPSS 0.1%CVE-2025-47389HIGHBuffer Copy Without Checking Size of Input in Automotive PlatformEPSS 0.1%CVE-2018-9402HIGHIn multiple functions of gl_proc.c, there is a buffer overwrite due to a missing bounds check. This could lead to escalation of privileges iEPSS 0.1%CVE-2026-56892MEDIUMIn ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could lead to local informEPSS 0.1%CVE-2022-47498MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2026-58839HIGHIn forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation ofEPSS 0.1%CVE-2022-47496MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2026-28580HIGHIn multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of prEPSS 0.1%CVE-2026-58695HIGHIn gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could EPSS 0.1%CVE-2022-47499MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-47491MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2026-49884HIGHIn rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local esEPSS 0.1%CVE-2022-47497MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-47494MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%CVE-2022-47495MEDIUMIn soter service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SysEPSS 0.1%