Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-64767CRITICALA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.8%CVE-2025-22913CRITICALRE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.EPSS 0.8%CVE-2023-3766MEDIUMInvalid Slice Split Results in Server PanicEPSS 0.8%CVE-2024-22472HIGHLong S0 frames received by 500 series Z-Wave devices may cause buffer overflowEPSS 0.8%CVE-2023-44828HIGHD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the CurrentPassword parameter in the CheckPasswdSettings functioEPSS 0.8%CVE-2026-4690CRITICALSandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM componentEPSS 0.8%CVE-2025-43501MEDIUMA buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 2EPSS 0.8%CVE-2023-4260MEDIUMPotential off-by-one buffer overflow vulnerability in the Zephyr FS subsystemEPSS 0.8%CVE-2022-42272HIGHNVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow, which may lead to code executEPSS 0.8%CVE-2025-12239HIGHTOTOLINK A3300R cstecgi.cgi setDdnsCfg buffer overflowEPSS 0.8%CVE-2025-12240HIGHTOTOLINK A3300R cstecgi.cgi setDmzCfg buffer overflowEPSS 0.8%CVE-2025-15089HIGHUTT 进取 512W APSecurity strcpy buffer overflowEPSS 0.8%CVE-2024-22419HIGHconcat built-in can corrupt memory in vyperEPSS 0.8%CVE-2025-15090HIGHUTT 进取 512W formConfigNoticeConfig strcpy buffer overflowEPSS 0.8%CVE-2023-50986HIGHTenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.EPSS 0.8%CVE-2024-7534HIGHHeap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.8%CVE-2026-43750CRITICALA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.8%CVE-2025-5330MEDIUMFreeFloat FTP Server RETR Command buffer overflowEPSS 0.8%CVE-2024-10371MEDIUMSourceCodester Payroll Management System main login buffer overflowEPSS 0.8%CVE-2023-2686CRITICALBuffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payloaEPSS 0.8%