Fallos del tipo CWE-125

5179 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2026-2662MEDIUMFascinatedBox lily lily_emitter.c count_transforms out-of-boundsEPSS 0.2%CVE-2023-0193MEDIUM NVIDIA CUDA Toolkit SDK contains a vulnerability in cuobjdump, where a local user running the tool against a malicious binary may cause an EPSS 0.2%CVE-2025-43221HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15EPSS 0.2%CVE-2025-43218MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafEPSS 0.2%CVE-2026-7933MEDIUMOut of bounds read in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read viEPSS 0.2%CVE-2026-0141MEDIUMIn decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information dEPSS 0.2%CVE-2024-0016MEDIUMIn multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information diEPSS 0.2%CVE-2026-11256HIGHInteger overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.2%CVE-2025-20026HIGHOut-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to poEPSS 0.2%CVE-2025-43366MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to disclose copEPSS 0.2%CVE-2024-56555HIGHbinder: fix OOB in binder_add_freeze_work()EPSS 0.2%CVE-2024-23439HIGHVba32 Antivirus v3.36.0 - Arbitrary Memory ReadEPSS 0.2%CVE-2024-28756MEDIUMThe SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MiEPSS 0.2%CVE-2026-2644MEDIUMniklasso minisat DIMACS File SolverTypes.h value out-of-boundsEPSS 0.2%CVE-2025-54260HIGHSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-23440HIGHVba32 Antivirus v3.36.0 - Arbitrary Memory ReadEPSS 0.2%CVE-2023-38529HIGHA vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35EPSS 0.2%CVE-2023-22295LOWCVE-2023-22295EPSS 0.2%CVE-2023-38525HIGHA vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35EPSS 0.2%CVE-2023-38530HIGHA vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35EPSS 0.2%