Fallos del tipo CWE-125

5159 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2026-69532HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-32391—The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.5, iOS 16.5 and iPadOS 16.5, maEPSS 0.3%CVE-2026-26153HIGHWindows Encrypted File System (EFS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50422HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69265HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-56176HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69324HIGHWindows Performance Monitor Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69561HIGHWindows CD-ROM Driver Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62876HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-70569HIGHWindows Spaceport.sys Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62880HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-65786HIGHDesktop Window Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-42387LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.3%CVE-2025-22392MEDIUMOut-of-bounds read in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable iEPSS 0.3%CVE-2022-42386LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.3%CVE-2023-26339MEDIUMZDI-CAN-19388: Adobe Dimension OBJ File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-26345MEDIUMZDI-CAN-19494: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-26338MEDIUMZDI-CAN-19410: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-26351MEDIUMZDI-CAN-19507: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-26354MEDIUMZDI-CAN-19519: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%