Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-42813CRITICALIn TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gEPSS 0.7%CVE-2023-32722CRITICALStack-buffer Overflow in library module zbxjsonEPSS 0.7%CVE-2026-2066HIGHUTT 进取 520W formIpGroupConfig strcpy buffer overflowEPSS 0.7%CVE-2026-76682HIGHUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.7%CVE-2026-2071HIGHUTT 进取 520W formP2PLimitConfig strcpy buffer overflowEPSS 0.7%CVE-2024-55194CRITICALOpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.EPSS 0.7%CVE-2026-2070HIGHUTT 进取 520W formPolicyRouteConf strcpy buffer overflowEPSS 0.7%CVE-2024-27128MEDIUMQTS, QuTS heroEPSS 0.7%CVE-2024-27129MEDIUMQTS, QuTS heroEPSS 0.7%CVE-2023-28116HIGHBuffer overflow in L2CAP due to misconfigured MTUEPSS 0.7%CVE-2025-12345HIGHLLM-Claw Agent Deployment initiate.c agent_deploy_init buffer overflowEPSS 0.7%CVE-2026-18279HIGHSony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-44331HIGHIncorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of servicEPSS 0.7%CVE-2023-40830CRITICALTenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.EPSS 0.7%CVE-2022-44232HIGHlibming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of service. This is a diffeEPSS 0.7%CVE-2026-71941HIGHDrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmailEPSS 0.7%CVE-2025-12611HIGHTenda AC21 SetPptpServerCfg formSetPPTPServer buffer overflowEPSS 0.7%CVE-2026-71942HIGHDrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalertEPSS 0.7%CVE-2026-71938HIGHDrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrpEPSS 0.7%CVE-2026-71911HIGHDrayTek VigorAP Multiple Models Buffer Overflow via setLanEPSS 0.7%