Fallos del tipo CWE-125

5159 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2024-32631HIGHOut-of-bounds read in telephonyEPSS 0.3%CVE-2024-49541MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-49548MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-49546MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-62353MEDIUMTDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetTokenEPSS 0.3%CVE-2026-69844HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69509HIGHRole: Windows Fax Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-65787HIGHDesktop Window Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69450HIGHWindows Error Reporting Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-34140MEDIUMAdobe Bridge PDF File Parsing Memory CorruptionEPSS 0.3%CVE-2026-44808HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62733HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-42837HIGHWindows Projected File System Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69295HIGHWindows USB Driver Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50399HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69312HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-70574HIGHVirtual Hard Disk (VHD) Miniport Driver Elevation of Privilege VulernabilityEPSS 0.3%CVE-2026-32076HIGHWindows Storage Spaces Controller Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69538HIGHWindows Spaceport.sys Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-50670HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%