Fallos del tipo CWE-125

5131 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2026-63521MEDIUMMicrosoft Office Word Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-70315MEDIUMMicrosoft Office Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-66806MEDIUMMicrosoft Office Word Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-38559MEDIUMGhostscript: out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in dosEPSS 0.4%CVE-2026-70310MEDIUMMicrosoft Word Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-77491MEDIUMWindows GDI Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-70298HIGHGPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.EPSS 0.4%CVE-2026-66809MEDIUMMicrosoft Office Graphics Component Information Disclosure VulnerabilityEPSS 0.4%CVE-2022-42417HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2026-33642CRITICALKitty has a Heap Buffer Over-Read/Write via Integer Overflow in compose_rectangles Bounds CheckEPSS 0.4%CVE-2023-42061HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-31897NONEFreeRDP has an out-of-bounds read in `freerdp_bitmap_decompress_planar`EPSS 0.4%CVE-2022-39836MEDIUMAn issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a craftedEPSS 0.4%CVE-2026-33069MEDIUMPJSIP has an Out-of-bounds Read in SIP multipart parsingEPSS 0.4%CVE-2026-79592HIGHAn out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controllEPSS 0.4%CVE-2026-41703HIGHOut-of-bounds read vulnerabilityEPSS 0.4%CVE-2025-24431MEDIUMAcrobat Reader | Out-of-bounds Read (CWE-125)EPSS 0.4%CVE-2024-39516HIGHJunos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crashEPSS 0.4%CVE-2026-48682MEDIUMFastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, aftEPSS 0.4%CVE-2023-42072LOWPDF-XChange Editor JPC File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%