Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-52908CRITICALAn issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580EPSS 0.5%CVE-2023-24584HIGHController 6000 buffer overflow via upload feature in web interfaceEPSS 0.5%CVE-2019-25232HIGHNetPCLinker 1.0.0.0 - Buffer OverflowEPSS 0.5%CVE-2026-28931HIGHA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6,EPSS 0.5%CVE-2023-48704HIGHUnauthenticated heap buffer overflow in Gorrila codec decompressionEPSS 0.5%CVE-2023-37245—Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availaEPSS 0.5%CVE-2025-26002CRITICALTelesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSynEPSS 0.5%CVE-2026-44436HIGHQuicly is vulnerable to connection state corruptionEPSS 0.5%CVE-2025-50670HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. AnEPSS 0.5%CVE-2022-23085CRITICALPotential jail escape vulnerabilities in netmapEPSS 0.5%CVE-2024-42642MEDIUMMicron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially craftedEPSS 0.5%CVE-2021-47815MEDIUMNsauditor 3.2.3 - Denial of Service (PoC)EPSS 0.5%CVE-2024-53379HIGHHeap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/24) commit 64808a5e12EPSS 0.5%CVE-2018-25125HIGHNetis DL4322D RTK 2.1.1 FTP Service DoSEPSS 0.5%CVE-2025-28019HIGHTOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi componentEPSS 0.5%CVE-2023-4263HIGHPotential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driverEPSS 0.5%CVE-2020-37010HIGHBearShare Lite 5.2.5 - 'Advanced Search'Buffer Overflow in (PoC)EPSS 0.5%CVE-2024-6918HIGHCWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the AccutecEPSS 0.5%CVE-2023-53874MEDIUMGOM Player 2.3.90.5360 Buffer Overflow via Equalizer Preset NameEPSS 0.5%CVE-2020-37130MEDIUMNsauditor 3.2.0.0 - 'Name' Denial of ServiceEPSS 0.5%