Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2020-11068MEDIUMPotential Buffer Overflow in LoRaMac-nodeEPSS 0.9%CVE-2022-50922HIGHAudio Conversion Wizard v2.01 - Buffer OverflowEPSS 0.9%CVE-2021-21281HIGHBuffer overflow due to unvalidated TCP data offsetEPSS 0.9%CVE-2025-6336HIGHTOTOLINK EX1200T HTTP POST Request formTmultiAP buffer overflowEPSS 0.9%CVE-2024-29159CRITICALHDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causinEPSS 0.9%CVE-2022-35021MEDIUMOTFCC commit 617837b was discovered to contain a global buffer overflow via /release-x64/otfccdump+0x718693.EPSS 0.9%CVE-2024-35823MEDIUMvt: fix unicode buffer corruption when deleting charactersEPSS 0.9%CVE-2025-5793HIGHTOTOLINK EX1200T HTTP POST Request formPortFw buffer overflowEPSS 0.9%CVE-2021-3182HIGHD-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerability only affects products that are no longer supported by the maintaineEPSS 0.9%CVE-2024-24451HIGHA stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackerEPSS 0.9%CVE-2025-6881HIGHD-Link DI-8100 jhttpd pppoe_base.asp buffer overflowEPSS 0.9%CVE-2023-28506HIGHStack buffer overflow in UniRPC serviceEPSS 0.9%CVE-2024-29506MEDIUMArtifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.EPSS 0.9%CVE-2022-45997HIGHTenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.EPSS 0.9%CVE-2023-36321HIGHConnected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component /shared/dlt_common.cEPSS 0.9%CVE-2023-46284HIGHA vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIEPSS 0.9%CVE-2023-46283HIGHA vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIEPSS 0.9%CVE-2022-27612HIGHBuffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Audio Station before 6.5.4EPSS 0.9%CVE-2024-34945CRITICALTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizaEPSS 0.9%CVE-2024-2452HIGHInteger wraparound, under-allocation, and heap buffer overflow in Eclipse ThreadX NetX Duo __portable_aligned_alloc()EPSS 0.9%