Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2022-45706CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.EPSS 1.1%CVE-2022-45715CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the EPSS 1.1%CVE-2022-45712CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.EPSS 1.1%CVE-2022-45710CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the forEPSS 1.1%CVE-2022-28550CRITICALMatthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer EPSS 1.1%CVE-2022-45719CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.EPSS 1.1%CVE-2022-45720CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBinEPSS 1.1%CVE-2022-45716CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.EPSS 1.1%CVE-2022-45718CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.EPSS 1.1%CVE-2020-22524MEDIUMBuffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service viEPSS 1.1%CVE-2023-22915HIGHA buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEPSS 1.1%CVE-2025-8136HIGHTOTOLINK A702R HTTP POST Request formFilter buffer overflowEPSS 1.1%CVE-2023-43131CRITICALGeneral Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.EPSS 1.1%CVE-2025-8137HIGHTOTOLINK A702R HTTP POST Request formIpQoS buffer overflowEPSS 1.1%CVE-2023-50245CRITICALOpenEXR-viewer memory overflow vulnerabilityEPSS 1.1%CVE-2025-7463HIGHTenda FH1201 HTTP POST Request AdvSetWrlsafeset formWrlsafeset buffer overflowEPSS 1.1%CVE-2025-8139HIGHTOTOLINK A702R HTTP POST Request formPortFw buffer overflowEPSS 1.1%CVE-2024-8079HIGHTOTOLINK AC1200 T8 exportOvpn buffer overflowEPSS 1.1%CVE-2022-20904MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.0%CVE-2022-20893MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service VulnerabilitiesEPSS 1.0%