Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-7583HIGHTenda i22 apPortalOneKeyAuth formApPortalOneKeyAuth buffer overflowEPSS 1.4%CVE-2024-7582HIGHTenda i22 apPortalAccessCodeAuth formApPortalAccessCodeAuth buffer overflowEPSS 1.4%CVE-2022-34823CRITICALBuffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SiEPSS 1.4%CVE-2023-26768HIGHBuffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the compileTranslationTabEPSS 1.4%CVE-2024-8579HIGHTOTOLINK AC1200 T8 cstecgi.cgi setWiFiRepeaterCfg buffer overflowEPSS 1.3%CVE-2024-7462HIGHTOTOLINK N350RT cstecgi.cgi setWizardCfg buffer overflowEPSS 1.3%CVE-2024-7465HIGHTOTOLINK CP450 cstecgi.cgi loginauth buffer overflowEPSS 1.3%CVE-2019-1010218—Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact isEPSS 1.3%CVE-2019-0160HIGHBuffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of EPSS 1.3%CVE-2025-8160HIGHTenda AC20 httpd SetSysTimeCfg buffer overflowEPSS 1.3%CVE-2024-39801CRITICALMultiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciallyEPSS 1.3%CVE-2022-28722CRITICALCertain HP Print Products are potentially vulnerable to Buffer Overflow.EPSS 1.3%CVE-2020-19695CRITICALBuffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vEPSS 1.3%CVE-2021-38111HIGHThe DEF CON 27 badge allows remote attackers to exploit a buffer overflow by sending an oversized packet via the NFMI (Near Field Magnetic IEPSS 1.3%CVE-2024-7585HIGHTenda i22 apPortalAuth formApPortalWebAuth buffer overflowEPSS 1.3%CVE-2021-45345HIGHBuffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service via the WebcamServeEPSS 1.3%CVE-2022-26649CRITICALA vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE EPSS 1.3%CVE-2026-2005HIGHPostgreSQL pgcrypto heap buffer overflow executes arbitrary codeEPSS 1.3%CVE-1999-0038HIGHBuffer overflow in xlock program allows local users to execute commands as root.EPSS 1.3%CVE-2023-7222HIGHTotolink X2000R HTTP POST Request boa formTmultiAP buffer overflowEPSS 1.3%