Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-20337HIGHClamAV ZIP File Format Processing Memory Corruption VulnerabilityEPSS 0.5%CVE-2026-28902MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS EPSS 0.5%CVE-2026-28875HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may be ablEPSS 0.5%CVE-2026-28847HIGHThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-28857MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visioEPSS 0.5%CVE-2026-28903MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOSEPSS 0.5%CVE-2026-28901MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS EPSS 0.5%CVE-2023-50246MEDIUMjq has heap-buffer-overflow vulnerability in the function decToString in decNumber.cEPSS 0.5%CVE-2026-78322MEDIUMFile-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar handlersEPSS 0.5%CVE-2023-40164MEDIUMNotepad++ global buffer read overflow in nsCodingStateMachine::NextStateEPSS 0.5%CVE-2022-25708CRITICALMemory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon MobileEPSS 0.5%CVE-2024-14044MEDIUMOpen5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflowEPSS 0.5%CVE-2020-8249—A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.EPSS 0.5%CVE-2024-39181MEDIUMShenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid parameter in thegeneraEPSS 0.5%CVE-2026-80186HIGHBluez: stack overflow in name2utf8 causes dos and potential code executionEPSS 0.5%CVE-2026-19969MEDIUMOpen Asset Import Library Assimp 3DGS MDL7 Model Output Mesh Generator MDLLoader.cpp GenerateOutputMeshes_3DGS_MDL7 buffer overflowEPSS 0.5%CVE-2026-2007HIGHPostgreSQL pg_trgm heap buffer overflow writes pattern onto server memoryEPSS 0.5%CVE-2024-8198HIGHHeap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to EPSS 0.5%CVE-2025-29365CRITICALspimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.EPSS 0.5%CVE-2025-52909CRITICALAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580EPSS 0.5%