Fallos del tipo CWE-125

5179 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2022-39137—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.2%CVE-2024-47436MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-39141—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.2%CVE-2024-56721HIGHx86/CPU/AMD: Terminate the erratum_1386_microcode arrayEPSS 0.2%CVE-2024-20787MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-41860MEDIUMAdobe Substance 3D Sampler Memory Corruption Vulnerability I, when parsing PSD fileEPSS 0.2%CVE-2024-50247HIGHfs/ntfs3: Check if more than chunk-size bytes are writtenEPSS 0.2%CVE-2024-30283MEDIUMAdobe FrameMaker ICO File Parsing Heap Memory CorruptionEPSS 0.2%CVE-2024-30287MEDIUMAdobe FrameMaker PDF File Pparsing Out of Bound ReadEPSS 0.2%CVE-2024-30286MEDIUMAdobe FrameMaker DOC File Parsing Memory CorruptionEPSS 0.2%CVE-2024-50128HIGHnet: wwan: fix global oob in wwan_rtnl_policyEPSS 0.2%CVE-2024-47456MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-50158HIGHRDMA/bnxt_re: Fix out of bound checkEPSS 0.2%CVE-2024-50208HIGHRDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pagesEPSS 0.2%CVE-2023-52070HIGHJFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: thisEPSS 0.2%CVE-2023-32289HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead tEPSS 0.2%CVE-2023-32545HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead EPSS 0.2%CVE-2024-20722MEDIUMAdobe Substance 3D Painter v9.0.1Build2822 OOBR Vulnerability IIIEPSS 0.2%CVE-2023-31278HIGHHorner Automation Cscape Out-of-bounds ReadEPSS 0.2%CVE-2023-32281HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to aEPSS 0.2%