Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-22419HIGHconcat built-in can corrupt memory in vyperEPSS 0.8%CVE-2023-50986HIGHTenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.EPSS 0.8%CVE-2024-7534HIGHHeap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.8%CVE-2026-43750CRITICALA buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.8%CVE-2025-5330MEDIUMFreeFloat FTP Server RETR Command buffer overflowEPSS 0.8%CVE-2024-10371MEDIUMSourceCodester Payroll Management System main login buffer overflowEPSS 0.8%CVE-2023-2686CRITICALBuffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payloaEPSS 0.8%CVE-2023-46271CRITICALExtreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui servEPSS 0.8%CVE-2026-2202HIGHTenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflowEPSS 0.8%CVE-2022-41484HIGHTenda AC1900 AP500(US)_V1_180320(Beta) was discovered to contain a buffer overflow in the 0x32384 function. This vulnerability allows attackEPSS 0.8%CVE-2022-41482HIGHTenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47c5dc function. This vulnerabilityEPSS 0.8%CVE-2026-1686HIGHTotolink A3600R app.so setAppEasyWizardConfig buffer overflowEPSS 0.8%CVE-2022-41480HIGHTenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x475dc function. This vulnerability EPSS 0.8%CVE-2026-2203HIGHTenda AC8 Embedded Httpd Service fast_setting_wifi_set buffer overflowEPSS 0.8%CVE-2023-32968MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2025-9443HIGHTenda CH22 editUserName formeditUserName buffer overflowEPSS 0.8%CVE-2026-42859HIGHNeat VNC: Buffer overflow due to oversized RSA public keysEPSS 0.8%CVE-2023-50362MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2024-57482CRITICALH3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing functEPSS 0.8%CVE-2024-57473CRITICALH3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. AttackEPSS 0.8%