Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-58823HIGHIn stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to locaEPSS 0.1%CVE-2025-36927HIGHIn GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a missing bounds check. This could lead to lEPSS 0.1%CVE-2025-36930HIGHIn GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatioEPSS 0.1%CVE-2025-36928HIGHIn GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalaEPSS 0.1%CVE-2023-20624MEDIUMIn vow, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with SystEPSS 0.1%CVE-2025-21426MEDIUMBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Camera_LinuxEPSS 0.1%CVE-2025-27043HIGHBuffer Copy Without Checking Size of Input in VideoEPSS 0.1%CVE-2023-21135—In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validatiEPSS 0.1%CVE-2025-27058HIGHBuffer Copy Without Checking Size of Input in Computer VisionEPSS 0.1%CVE-2025-27052HIGHBuffer Copy Without Checking Size of Input in Core ServicesEPSS 0.1%CVE-2022-48439MEDIUMIn cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with SyEPSS 0.1%CVE-2024-53013MEDIUMBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2024-25984MEDIUMIn dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local inforEPSS 0.1%CVE-2022-47487MEDIUMIn thermal service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service local EPSS 0.1%CVE-2025-21444HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Data HLOS - QXEPSS 0.1%CVE-2026-55290LOWIn setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local informatiEPSS 0.1%CVE-2025-21445HIGHBuffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Data HLOS - QXEPSS 0.1%CVE-2025-47341HIGHBuffer Copy Without Checking Size of Input in CameraEPSS 0.1%CVE-2025-21476HIGHBuffer Copy Without Checking Size of Input in Computer VisionEPSS 0.1%CVE-2024-27225MEDIUMIn sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informEPSS 0.1%