Fallos del tipo CWE-125

5179 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2025-7252HIGHIrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-61799HIGHDimension | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-7267HIGHIrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-43551MEDIUMSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-34961MEDIUMbarebox ext4 Extent Parsing Out-of-Bounds ReadEPSS 0.2%CVE-2018-9429MEDIUMIn buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to informatioEPSS 0.2%CVE-2024-50259MEDIUMnetdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()EPSS 0.2%CVE-2025-1659HIGHDWFX File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2025-1658HIGHDWFX File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2026-84270MEDIUMGvfs: mtp: out-of-bounds read in do_read()EPSS 0.2%CVE-2025-49525MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54262HIGHSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-30795HIGHA vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4), Parasolid V34.0 (All versions < EPSS 0.2%CVE-2023-29939MEDIUMllvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv:EPSS 0.2%CVE-2025-30313MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-24558HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2021-29551LOWOOB read in `MatrixTriangularSolve`EPSS 0.2%CVE-2026-43753MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, maEPSS 0.2%CVE-2023-33123HIGHA vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), TeamcenEPSS 0.2%CVE-2023-30796HIGHA vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4). The affected applications contaiEPSS 0.2%