Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-18103MEDIUMDhcp-server: dhcp-server: persistent denial of service due to buffer overflow via omapiEPSS 0.7%CVE-2026-75124HIGHPLANET GS-4210-16P2S V3 Memory Corruption via dispatcher.cgi _readHttpParamEPSS 0.7%CVE-2025-5110MEDIUMFreeFloat FTP Server VERBOSE Command buffer overflowEPSS 0.7%CVE-2025-5635MEDIUMPCMan FTP Server PLS Command buffer overflowEPSS 0.7%CVE-2025-5634MEDIUMPCMan FTP Server NOOP Command buffer overflowEPSS 0.7%CVE-2025-5109MEDIUMFreeFloat FTP Server STATUS Command buffer overflowEPSS 0.7%CVE-2025-4792MEDIUMFreeFloat FTP Server MDELETE Command buffer overflowEPSS 0.7%CVE-2025-5076MEDIUMFreeFloat FTP Server SEND Command buffer overflowEPSS 0.7%CVE-2025-5049MEDIUMFreeFloat FTP Server APPEND Command buffer overflowEPSS 0.7%CVE-2025-5112MEDIUMFreeFloat FTP Server MGET Command buffer overflowEPSS 0.7%CVE-2025-5295MEDIUMFreeFloat FTP Server PORT Command buffer overflowEPSS 0.7%CVE-2025-5050MEDIUMFreeFloat FTP Server BELL Command buffer overflowEPSS 0.7%CVE-2025-5111MEDIUMFreeFloat FTP Server TYPE Command buffer overflowEPSS 0.7%CVE-2024-48150CRITICALD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.EPSS 0.7%CVE-2025-24157MEDIUMA buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS VEPSS 0.7%CVE-2024-38952HIGHPX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.EPSS 0.7%CVE-2025-5220MEDIUMFreeFloat FTP Server GET Command buffer overflowEPSS 0.7%CVE-2026-24660HIGHA heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted maliciEPSS 0.7%CVE-2023-36358HIGHTP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /EPSS 0.7%CVE-2025-5075MEDIUMFreeFloat FTP Server DEBUG Command buffer overflowEPSS 0.7%