Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2019-14835HIGHA buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue EPSS 0.6%CVE-2026-63453HIGHAuthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CXEPSS 0.6%CVE-2024-42011HIGHThe Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.EPSS 0.6%CVE-2026-20652HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOSEPSS 0.6%CVE-2022-43392MEDIUMA buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an autheEPSS 0.6%CVE-2023-23494MEDIUMA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user in a privileged netwoEPSS 0.6%CVE-2025-25565CRITICALSoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the SuEPSS 0.6%CVE-2025-15460HIGHUTT 进取 520W formPptpClientConfig strcpy buffer overflowEPSS 0.6%CVE-2024-37863CRITICALOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl procEPSS 0.6%CVE-2024-52754LOWD-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.EPSS 0.6%CVE-2024-45970CRITICALMultiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a maliEPSS 0.6%CVE-2024-45971CRITICALMultiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a maliEPSS 0.6%CVE-2026-7735MEDIUMosrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflowEPSS 0.6%CVE-2024-40084CRITICALA Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to execute arbitraryEPSS 0.6%CVE-2024-40085CRITICALA Buffer Overflow vulnerability in the local_app_set_router_wan function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticaEPSS 0.6%CVE-2024-40086CRITICALA Buffer Overflow vulnerability in the local_app_set_router_wifi_SSID_PWD function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unEPSS 0.6%CVE-2025-49464MEDIUMZoom Clients for Windows- Classic Buffer OverflowEPSS 0.6%CVE-2022-43389HIGHA buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unaEPSS 0.6%CVE-2020-37069HIGHKonica Minolta FTP Utility 1.0 - 'NLST' Denial of ServiceEPSS 0.6%CVE-2025-14140HIGHUTT 进取 520W websHostFilter strcpy buffer overflowEPSS 0.6%