Fallos del tipo CWE-125

5130 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2024-0107HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-oEPSS 0.5%CVE-2026-64784MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7EPSS 0.5%CVE-2025-55087MEDIUMIn NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by aEPSS 0.5%CVE-2025-36521HIGHMicroDicom DICOM Viewer Out-of-bounds ReadEPSS 0.5%CVE-2025-27891CRITICALAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.5%CVE-2026-31965MEDIUMHTSlib CRAM reader has out-of-bounds reads due to improper validation of inputEPSS 0.5%CVE-2026-50278MEDIUMiccDEV: CIccEmbedIO::Read8() size_t underflowEPSS 0.5%CVE-2025-4082MEDIUMWebGL shader attribute memory corruption in Thunderbird for macOSEPSS 0.5%CVE-2026-63409HIGHDeskflow: Odd-length DSOP options vector causes out-of-bounds read in Deskflow clientEPSS 0.5%CVE-2023-42088HIGHPDF-XChange Editor JPG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42058HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-43909HIGHOpenImageIO: Signed integer overflow in SwapRGBABytes loop index leads to out-of-bounds read/write in DPX ABGR decoderEPSS 0.5%CVE-2024-53004MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.5%CVE-2021-3588LOWmemory contents disclosure in cli_feat_read_cbEPSS 0.4%CVE-2025-57812LOW[BIGSLEEP-434612419] CUPS-Filters has heap-buffer-overflow write in `cfImageLut()`EPSS 0.4%CVE-2026-60065MEDIUMNGINX Plus ngx_stream_mqtt_filter_module vulnerabilityEPSS 0.4%CVE-2024-40630MEDIUMHEIF Heap OOB Read in OpenImageIOEPSS 0.4%CVE-2026-16853MEDIUMIBM i is Affected By Multiple Vulnerabilities in NetServerEPSS 0.4%CVE-2021-31431MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An EPSS 0.4%CVE-2021-31430MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An EPSS 0.4%