Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-34945CRITICALTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizaEPSS 0.9%CVE-2023-44831HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Type parameter in the SetWLanRadioSettings function. This vuEPSS 0.9%CVE-2023-27971CRITICALCertain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.EPSS 0.9%CVE-2023-28508—Heap corruption in UniRPC serviceEPSS 0.9%CVE-2025-22946CRITICALTenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitraryEPSS 0.9%CVE-2025-8939HIGHTenda AC20 WifiGuestSet buffer overflowEPSS 0.9%CVE-2023-27065HIGHTenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the formDelEPSS 0.9%CVE-2023-27062HIGHTenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This vulneEPSS 0.9%CVE-2023-27064HIGHTenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the formDelDnEPSS 0.9%CVE-2025-6940HIGHTOTOLINK A702R HTTP POST Request formParentControl buffer overflowEPSS 0.9%CVE-2025-15428HIGHUTT 进取 512W formRemoteControl strcpy buffer overflowEPSS 0.9%CVE-2025-43441MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOSEPSS 0.9%CVE-2022-23477CRITICALBuffer Overflow in xrdpEPSS 0.9%CVE-2025-6953HIGHTOTOLINK A3002RU HTTP POST Request formParentControl buffer overflowEPSS 0.9%CVE-2024-38541HIGHof: module: add buffer overflow check in of_modalias()EPSS 0.9%CVE-2022-23480CRITICALBuffer Overflow in xrdpEPSS 0.9%CVE-2022-23479CRITICALBuffer Overflow occurs in xrdpEPSS 0.9%CVE-2025-15461HIGHUTT 进取 520W formTaskEdit strcpy buffer overflowEPSS 0.9%CVE-2025-15429HIGHUTT 进取 512W formConfigCliForEngineerOnly strcpy buffer overflowEPSS 0.9%CVE-2024-23972MEDIUMSony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.9%