Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2023-32971LOWQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-41275MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-32973LOWQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2023-32972LOWQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2026-57874HIGHGV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_upload.cgi)EPSS 0.5%CVE-2024-31951MEDIUMIn the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_EPSS 0.5%CVE-2023-37929MEDIUMThe buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remotEPSS 0.5%CVE-2018-4301CRITICALThis issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp.EPSS 0.5%CVE-2025-7673CRITICALA buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 EPSS 0.5%CVE-2026-43658HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadEPSS 0.5%CVE-2026-28904HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-76705MEDIUMAuthenticated Buffer Overflow Vulnerability in an API Endpoint Leads to Remote Code Execution in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2026-28905HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS EPSS 0.5%CVE-2026-28953HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2023-46960HIGHBuffer Overflow vulnerability in PyPXE v.1.8.4 allows a remote attacker to cause a denial of service via the handle function in the tftp modEPSS 0.5%CVE-2023-52309HIGHHeap buffer overflow in paddle.repeat_interleaveEPSS 0.5%CVE-2024-57578MEDIUMTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm function.EPSS 0.5%CVE-2025-4440HIGHH3C GR-1800AX aspForm EnableIpv6 buffer overflowEPSS 0.5%CVE-2025-29137CRITICALTenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cEPSS 0.5%CVE-2025-4446HIGHH3C GR-5400AX aspForm Edit_List_SSID buffer overflowEPSS 0.5%