Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-70415HIGHDell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remotEPSS 0.6%CVE-2020-37068HIGHKonica Minolta FTP Utility 1.0 - 'LIST' Denial of ServiceEPSS 0.6%CVE-2025-4117MEDIUMNetgear JWNR2000v2 sub_41A914 buffer overflowEPSS 0.6%CVE-2026-48706MEDIUMEnvoy Heap Buffer Overflow in TcpStatsdSinkEPSS 0.6%CVE-2026-15565HIGHUndertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serverendpoint class with any @onmessage methodEPSS 0.6%CVE-2022-37910MEDIUMA buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denEPSS 0.6%CVE-2025-46108CRITICALD-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.EPSS 0.6%CVE-2024-6343MEDIUMA buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware EPSS 0.6%CVE-2025-45861CRITICALTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.EPSS 0.6%CVE-2025-45863CRITICALTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interfaceEPSS 0.6%CVE-2025-45865CRITICALTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.EPSS 0.6%CVE-2024-39134HIGHA Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() EPSS 0.6%CVE-2017-14454HIGHMultiple exploitable buffer overflow vulnerabilities exists in the PubNub message handler for the "control" channel of Insteon Hub running fEPSS 0.6%CVE-2026-87931CRITICALBehavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflowEPSS 0.6%CVE-2026-4177CRITICALYAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitterEPSS 0.6%CVE-2026-11517HIGHUTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflowEPSS 0.6%CVE-2025-50666HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endEPSS 0.6%CVE-2025-50665HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endEPSS 0.6%CVE-2024-42040HIGHBuffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allowEPSS 0.6%CVE-2026-34875CRITICALAn issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.EPSS 0.6%