Fallos del tipo CWE-125

5159 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2025-43344LOWAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOSEPSS 0.3%CVE-2021-36060MEDIUMAdobe Media Encoder MPEG File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2020-1824LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2025-46316MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS TahoeEPSS 0.3%CVE-2025-43265MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS SequEPSS 0.3%CVE-2026-24189HIGHNVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliEPSS 0.3%CVE-2026-69549HIGHVirtual Hard Disk (VHD) Miniport Driver Elevation of Privilege VulernabilityEPSS 0.3%CVE-2026-35217MEDIUMNanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds ReadEPSS 0.3%CVE-2023-48638MEDIUMAdobe Substance 3D Designer 13.0.2 build 6942 Vulnerability IIIEPSS 0.3%CVE-2026-44067LOWEA header parsing heap over-readEPSS 0.3%CVE-2026-41034MEDIUMONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and othEPSS 0.3%CVE-2026-15114HIGHOut of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corrupEPSS 0.3%CVE-2023-47081MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability IIEPSS 0.3%CVE-2023-47080MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VIEPSS 0.3%CVE-2026-9121HIGHOut of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.3%CVE-2023-48636MEDIUMAdobe Substance 3D Designer 13.0.2 build 6942 Vulnerability IVEPSS 0.3%CVE-2026-7354HIGHOut of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox esEPSS 0.3%CVE-2023-51559LOWFoxit PDF Reader Doc Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-47520HIGHAn issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in theEPSS 0.3%CVE-2026-68891MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.3%