Fallos del tipo CWE-125
5177 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2025-53055MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions thEPSS 0.2%CVE-2023-32363—A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Ventura 13.4. An apEPSS 0.2%CVE-2024-54108MEDIUMRead/Write vulnerability in the image decoding module
Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.2%CVE-2026-93543HIGHOut-of-bounds read in libXi's XI2 class parserEPSS 0.2%CVE-2025-53065MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions thEPSS 0.2%CVE-2024-20790MEDIUMAdobe Dimension Memory Corruption Out-of-Bounds-READ Vulnerability I, when parsing FBX fileEPSS 0.2%CVE-2024-45464HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2025-30308MEDIUMXMPWorker | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-32916MEDIUMAn out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issEPSS 0.2%CVE-2024-34135MEDIUMAdobe Illustrator CC 2023 v27.9 Vulnerability IIEPSS 0.2%CVE-2024-34134MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-51456MEDIUMA Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attackEPSS 0.2%CVE-2024-31412HIGHOut-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially craftedEPSS 0.2%CVE-2024-45466HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2024-41868MEDIUMAudition | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-20798MEDIUMIllustrator 2024 CDR File parsing Out of Bound Read Information disclosure vulnerabilityEPSS 0.2%CVE-2024-45465HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2023-27945MEDIUMThis issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandbEPSS 0.2%CVE-2024-20793MEDIUMIllustrator 2024 TIF file parsing Out Of Bound Read Information disclosure vulnerabilityEPSS 0.2%CVE-2024-50115HIGHKVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memoryEPSS 0.2%