Weaknesses of type CWE-125

5,179 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2022-39137—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.2%CVE-2024-47436MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-39141—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.2%CVE-2024-56721HIGHx86/CPU/AMD: Terminate the erratum_1386_microcode arrayEPSS 0.2%CVE-2024-20787MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-41860MEDIUMAdobe Substance 3D Sampler Memory Corruption Vulnerability I, when parsing PSD fileEPSS 0.2%CVE-2024-50247HIGHfs/ntfs3: Check if more than chunk-size bytes are writtenEPSS 0.2%CVE-2024-30283MEDIUMAdobe FrameMaker ICO File Parsing Heap Memory CorruptionEPSS 0.2%CVE-2024-30287MEDIUMAdobe FrameMaker PDF File Pparsing Out of Bound ReadEPSS 0.2%CVE-2024-30286MEDIUMAdobe FrameMaker DOC File Parsing Memory CorruptionEPSS 0.2%CVE-2024-50128HIGHnet: wwan: fix global oob in wwan_rtnl_policyEPSS 0.2%CVE-2024-47456MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-50158HIGHRDMA/bnxt_re: Fix out of bound checkEPSS 0.2%CVE-2024-50208HIGHRDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pagesEPSS 0.2%CVE-2023-52070HIGHJFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: thisEPSS 0.2%CVE-2023-32289HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead tEPSS 0.2%CVE-2023-32545HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead EPSS 0.2%CVE-2024-20722MEDIUMAdobe Substance 3D Painter v9.0.1Build2822 OOBR Vulnerability IIIEPSS 0.2%CVE-2023-31278HIGHHorner Automation Cscape Out-of-bounds ReadEPSS 0.2%CVE-2023-32281HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to aEPSS 0.2%