Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-5636MEDIUMPCMan FTP Server SET Command buffer overflowEPSS 0.7%CVE-2025-5547MEDIUMFreeFloat FTP Server CDUP Command buffer overflowEPSS 0.7%CVE-2025-5549MEDIUMFreeFloat FTP Server PASV Command buffer overflowEPSS 0.7%CVE-2025-5593MEDIUMFreeFloat FTP Server HOST Command buffer overflowEPSS 0.7%CVE-2025-5550MEDIUMFreeFloat FTP Server PBSZ Command buffer overflowEPSS 0.7%CVE-2025-1147LOWGNU Binutils nm nm.c internal_strlen buffer overflowEPSS 0.7%CVE-2024-46601HIGHElspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.EPSS 0.7%CVE-2023-6711MEDIUMVulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially EPSS 0.7%CVE-2026-48490MEDIUMArduinoCore-AVR: Stack-Based Buffer Overflow in String float/double concatenation handlerEPSS 0.7%CVE-2025-5667MEDIUMFreeFloat FTP Server REIN Command buffer overflowEPSS 0.7%CVE-2026-4689CRITICALSandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM componentEPSS 0.7%CVE-2024-49777HIGHA heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS), Information DEPSS 0.7%CVE-2026-84609CRITICALA permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS SeEPSS 0.7%CVE-2023-34336HIGHAMI BMC contains a vulnerability in the IPMI handler, where an attacker with the required privileges can cause a buffer overflow, which may EPSS 0.7%CVE-2025-9782HIGHTOTOLINK A702R formOneKeyAccessButton sub_4466F8 buffer overflowEPSS 0.7%CVE-2025-9779HIGHTOTOLINK A702R formFilter sub_4162DC buffer overflowEPSS 0.7%CVE-2025-9783HIGHTOTOLINK A702R formParentControl sub_418030 buffer overflowEPSS 0.7%CVE-2025-9780HIGHTOTOLINK A702R formIpQoS sub_419BE0 buffer overflowEPSS 0.7%CVE-2025-9781HIGHTOTOLINK A702R formFilter sub_4162DC buffer overflowEPSS 0.7%CVE-2024-42543HIGHTOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.EPSS 0.7%