Fallos del tipo CWE-125

5179 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2026-7904MEDIUMOut of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a EPSS 0.2%CVE-2025-30302MEDIUMAdobe Framemaker | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-11160MEDIUMOut of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive inforEPSS 0.2%CVE-2025-30303MEDIUMAdobe Framemaker | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-7983MEDIUMOut of bounds read in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML paEPSS 0.2%CVE-2026-11051MEDIUMOut of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive inforEPSS 0.2%CVE-2026-11075MEDIUMOut of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from EPSS 0.2%CVE-2024-20787MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-50128HIGHnet: wwan: fix global oob in wwan_rtnl_policyEPSS 0.2%CVE-2024-47456MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-41863MEDIUMAdobe Substance 3D Sampler Memory Corruption Out-of-Bounds-READ Vulnerability III, when parsing DNG fileEPSS 0.2%CVE-2022-39141—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.2%CVE-2024-47437MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-41645HIGHOut-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrarEPSS 0.2%CVE-2024-30287MEDIUMAdobe FrameMaker PDF File Pparsing Out of Bound ReadEPSS 0.2%CVE-2024-30286MEDIUMAdobe FrameMaker DOC File Parsing Memory CorruptionEPSS 0.2%CVE-2024-47454MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-47449MEDIUMAudition | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-39137—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.2%CVE-2024-47440MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%