Fallos del tipo CWE-125

5177 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2025-5166MEDIUMOpen Asset Import Library Assimp MDC File Parser MDCLoader.cpp InternReadFile out-of-boundsEPSS 0.3%CVE-2023-42982MEDIUMProcessing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was adEPSS 0.3%CVE-2020-1820LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2025-24092MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able tEPSS 0.3%CVE-2026-17550MEDIUMDWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCADEPSS 0.3%CVE-2020-1822LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2020-1818LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2020-1823LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2022-21226MEDIUMOut-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable EPSS 0.3%CVE-2020-1819LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2026-12548MEDIUMLibsoup: heap out-of-bounds read in libsoup due to integer truncationEPSS 0.3%CVE-2020-1821LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2024-49197MEDIUMAn issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W93EPSS 0.3%CVE-2026-28527LOWBlueKitchen BTstack < 1.8.1 AVRCP Controller GET_PLAYER_APPLICATION_SETTING_*_TEXT Handlers OOB ReadEPSS 0.3%CVE-2026-11061CRITICALType Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.3%CVE-2021-47636HIGHubifs: Fix read out-of-bounds in ubifs_wbuf_write_nolock()EPSS 0.3%CVE-2026-102712HIGHOn the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against theEPSS 0.3%CVE-2023-27854HIGHRockwell Automation Arena® Simulation Out of Bounds Read VulnerabilityEPSS 0.3%CVE-2023-0969LOWGlobal read overflow in Z/IP GatewayEPSS 0.3%CVE-2026-0127MEDIUMIn NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This coEPSS 0.3%