Fallos del tipo CWE-120

3169 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2023-52346MEDIUMIn modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with SysEPSS 0.1%CVE-2025-27072MEDIUMBuffer Copy Without Checking Size of Input in Automotive Vehicle NetworksEPSS 0.1%CVE-2018-9403HIGHIn the MTK_FLP_MSG_HAL_DIAG_REPORT_DATA_NTF handler of flp2hal_- interface.c, there is a possible stack buffer overflow due to a missingEPSS 0.1%CVE-2018-9386MEDIUMIn reboot_block_command of htc reboot_block driver, there is a possible stack buffer overflow due to a missing bounds check. This could EPSS 0.1%CVE-2023-21143—In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could leEPSS 0.1%CVE-2022-47336MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47362MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47335MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47463MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2022-47464MEDIUMIn telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.EPSS 0.1%CVE-2025-47334MEDIUMBuffer Copy Without Checking Size of Input in Camera DriverEPSS 0.1%CVE-2025-47335MEDIUMBuffer Copy Without Checking Size of Input in Camera DriverEPSS 0.1%CVE-2024-40659MEDIUMIn getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation featEPSS 0.1%CVE-2024-47032HIGHIn construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead toEPSS 0.1%CVE-2025-47321HIGHBuffer Copy Without Checking Size of Input in Core ServicesEPSS 0.1%CVE-2025-26434MEDIUMIn libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additioEPSS 0.1%CVE-2017-13308MEDIUMIn tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validaEPSS 0.1%CVE-2025-47394HIGHBuffer Copy Without Checking Size of Input in DSP ServiceEPSS 0.1%CVE-2025-31712MEDIUMIn cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no EPSS 0.1%CVE-2025-47388HIGHBuffer Copy without Checking Size of Input in DSP ServiceEPSS 0.1%