Fallos del tipo CWE-125

5126 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2022-38441HIGHAdobe Dimension GLB File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-38440HIGHAdobe Dimension SKP File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-29309MEDIUM[FG-VD-23-003] Adobe InDesign 2023 Out-of-Bound Read Vulnerability NotificationEPSS 0.5%CVE-2023-29315MEDIUM[FG-VD-23-008] Adobe InDesign 2023 Out-of-Bound Read Vulnerability VI NotificationEPSS 0.5%CVE-2026-50811MEDIUMAn out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truEPSS 0.5%CVE-2024-54937MEDIUMA Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files EPSS 0.5%CVE-2024-30356LOWFoxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2022-41895MEDIUM`MirrorPadGrad` heap out of bounds read in TensorflowEPSS 0.5%CVE-2022-41897MEDIUM`FractionalMaxPoolGrad` Heap out of bounds read in TensorflowEPSS 0.5%CVE-2024-30340LOWFoxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2022-48479CRITICALThe facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability maEPSS 0.5%CVE-2022-44502MEDIUMAdobe Illustrator Font Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-55898MEDIUMMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-3407MEDIUMNothings stb stbhw_build_tileset_from_image out-of-boundsEPSS 0.5%CVE-2024-52876HIGHHoly Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remoteEPSS 0.5%CVE-2022-38412HIGHAdobe Animate SVG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-23333MEDIUMNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-ofEPSS 0.5%CVE-2026-25898MEDIUMImagemagick Has Global Buffer Overflow (OOB Read) via Negative Pixel Index in UIL and XPM WriterEPSS 0.5%CVE-2026-82618MEDIUMSysterel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matrix_on_string_array out-of-boundsEPSS 0.5%CVE-2026-87961HIGHESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed Length Parameter in read_ID3_HeaderEPSS 0.5%