Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-39769CRITICALMultiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciallyEPSS 0.9%CVE-2024-25139CRITICALIn TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffeEPSS 0.9%CVE-2024-39802CRITICALMultiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciallyEPSS 0.9%CVE-2022-49058CRITICALcifs: potential buffer overflow in handling symlinksEPSS 0.9%CVE-2025-1852HIGHTotolink EX1800T cstecgi.cgi loginAuth buffer overflowEPSS 0.9%CVE-2025-9813HIGHTenda CH22 SetSambaConf formSetSambaConf buffer overflowEPSS 0.9%CVE-2025-11408HIGHD-Link DI-7001 MINI dbsrv.asp buffer overflowEPSS 0.9%CVE-2025-7914HIGHTenda AC6 httpd setparentcontrolinfo buffer overflowEPSS 0.9%CVE-2025-24209HIGHA buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17EPSS 0.9%CVE-2020-23257HIGHBuffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMaEPSS 0.9%CVE-2023-4257HIGHUnchecked user input length in the Zephyr WiFi shell moduleEPSS 0.9%CVE-2024-32664MEDIUMSuricata's base64 contains an out of bounds writeEPSS 0.9%CVE-2023-5753MEDIUMPotential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystemEPSS 0.9%CVE-2023-32975MEDIUMQTS, QuTS heroEPSS 0.9%CVE-2023-49468HIGHLibde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.EPSS 0.9%CVE-2025-10756HIGHUTT HiPER 840G getOneApConfTempEntry buffer overflowEPSS 0.9%CVE-2022-24023CRITICALA buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuEPSS 0.9%CVE-2025-8940HIGHTenda AC20 saveParentControlInfo strcpy buffer overflowEPSS 0.9%CVE-2024-30259HIGHFastDDS heap buffer overflow when publisher sends malformed packetEPSS 0.9%CVE-2023-44833HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the GuardInt parameter in the SetWLanRadioSettings function. ThiEPSS 0.9%