Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-24447MEDIUMA buffer overflow in the ngap_amf_handle_pdu_session_resource_setup_response function of oai-cn5g-amf up to v2.0.0 allows attackers to causeEPSS 0.5%CVE-2021-34780MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.5%CVE-2021-34779MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.5%CVE-2024-33783MEDIUMMP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SileEPSS 0.5%CVE-2025-3854HIGHH3C GR-3000AX HTTP POST Request aspForm Edit_List_SSID buffer overflowEPSS 0.5%CVE-2024-8748HIGHA buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through EPSS 0.5%CVE-2024-13503CRITICALStack-Based Buffer Overflow in Newtec's update signaling causes RCEEPSS 0.5%CVE-2024-25165HIGHA global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.EPSS 0.5%CVE-2026-41476HIGHDeskflow: clipboard deserialization global-buffer-overflowEPSS 0.5%CVE-2023-43907HIGHOptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.EPSS 0.5%CVE-2023-40031HIGHNotepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convertEPSS 0.5%CVE-2024-37606MEDIUMA Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTEPSS 0.5%CVE-2025-50650HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameteEPSS 0.5%CVE-2025-50649HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shutEPSS 0.5%CVE-2025-50644HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint.EPSS 0.5%CVE-2025-50648HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint.EPSS 0.5%CVE-2025-50645HIGHA vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_listEPSS 0.5%CVE-2025-50647HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoEPSS 0.5%CVE-2026-70465HIGHA buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FEPSS 0.5%CVE-2025-50654HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp enEPSS 0.5%