Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2021-38689HIGHStack Overflow Vulnerability in QVR Elite, QVR Pro and QVR GuardEPSS 1.3%CVE-2021-38692HIGHStack Overflow Vulnerability in QVR Elite, QVR Pro and QVR GuardEPSS 1.3%CVE-2025-6113HIGHTenda FH1203 AdvSetLanip fromadvsetlanip buffer overflowEPSS 1.3%CVE-2025-6112HIGHTenda FH1205 AdvSetLanip fromadvsetlanip buffer overflowEPSS 1.3%CVE-2022-20885MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.3%CVE-2022-20881MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.3%CVE-2022-20876MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.3%CVE-2022-20874MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.3%CVE-2022-20877MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.3%CVE-2022-20875MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.3%CVE-2022-20878MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.3%CVE-2022-20884MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.3%CVE-2022-20882MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.3%CVE-2024-31225HIGHLack of size check and buffer overflow in RIOTEPSS 1.3%CVE-2021-20027—A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted requesEPSS 1.3%CVE-2021-32771HIGHBuffer overflow in contiki-ngEPSS 1.3%CVE-2023-51885CRITICALBuffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX stEPSS 1.3%CVE-2023-23305CRITICALThe GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. AEPSS 1.3%CVE-2021-38687HIGHStack Overflow Vulnerability in Surveillance StationEPSS 1.3%CVE-2025-24131MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, mEPSS 1.3%