Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-27628HIGHBuffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.EPSS 0.7%CVE-2025-4790MEDIUMFreeFloat FTP Server GLOB Command buffer overflowEPSS 0.7%CVE-2025-4788MEDIUMFreeFloat FTP Server DELETE Command buffer overflowEPSS 0.7%CVE-2025-9007HIGHTenda CH22 editFileName formeditFileName buffer overflowEPSS 0.7%CVE-2025-4791MEDIUMFreeFloat FTP Server HASH Command buffer overflowEPSS 0.7%CVE-2025-4789MEDIUMFreeFloat FTP Server LCD Command buffer overflowEPSS 0.7%CVE-2024-0144MEDIUMNVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a buffer overflow issue by means of a specially crafted JPEG2EPSS 0.7%CVE-2023-4055—When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent witEPSS 0.7%CVE-2024-40568CRITICALBuffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute aEPSS 0.7%CVE-2024-53334HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.EPSS 0.7%CVE-2024-44555CRITICALTenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.EPSS 0.7%CVE-2025-13549HIGHD-Link DIR-822K formNtp sub_455524 buffer overflowEPSS 0.7%CVE-2025-6751HIGHLinksys E8450 HTTP POST Request portal.cgi set_device_language buffer overflowEPSS 0.7%CVE-2024-30602CRITICALTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.EPSS 0.7%CVE-2022-44178CRITICALTenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.EPSS 0.7%CVE-2022-44174CRITICALTenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.EPSS 0.7%CVE-2022-44180CRITICALTenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.EPSS 0.7%CVE-2022-44172CRITICALTenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.EPSS 0.7%CVE-2022-44171CRITICALTenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.EPSS 0.7%CVE-2022-44177CRITICALTenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.EPSS 0.7%