Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-50645HIGHA vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_listEPSS 0.5%CVE-2025-50649HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shutEPSS 0.5%CVE-2023-22745MEDIUMBuffer Overlow in TSS2_RC_Decode in tpm2-tssEPSS 0.5%CVE-2023-47625LOWGlobal Buffer Overflow leading to denial of service in PX4-AutopilotEPSS 0.5%CVE-2025-25280MEDIUMBuffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by CenEPSS 0.5%CVE-2018-25426HIGHWinMTR 0.91 Denial of Service via Buffer OverflowEPSS 0.5%CVE-2024-12373CRITICALRockwell Automation PowerMonitor™ 1000 Denial of ServiceEPSS 0.5%CVE-2024-31950MEDIUMIn FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt tEPSS 0.5%CVE-2025-29363HIGHTenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to buffer overflow via the schedStartTime and schedEndTime parameters at /gofoEPSS 0.5%CVE-2025-29360HIGHTenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the time and timeZone parameters at /goform/SetSysTimeCEPSS 0.5%CVE-2024-53695MEDIUMHBS 3 Hybrid Backup SyncEPSS 0.5%CVE-2024-55564CRITICALThe POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.EPSS 0.5%CVE-2025-29359HIGHTenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the deviceId parameter at /goform/saveParentControlInfoEPSS 0.5%CVE-2023-25642MEDIUMTwo Vulnerabilities in Some ZTE Mobile Internet ProductsEPSS 0.5%CVE-2025-29362HIGHTenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/setPptpUserList. This vulEPSS 0.5%CVE-2025-55602CRITICALD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formSysCmd function via the submit-url parameter.EPSS 0.5%CVE-2024-9197MEDIUMA post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions thrEPSS 0.5%CVE-2024-41435HIGHYugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.EPSS 0.5%CVE-2026-28955HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-20337HIGHClamAV ZIP File Format Processing Memory Corruption VulnerabilityEPSS 0.5%