Fallos del tipo CWE-125

5180 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2023-49144HIGHOut of bounds read in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.15-0, bhs-0.27 may allow a privileged user tEPSS 0.2%CVE-2026-28832HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS TEPSS 0.2%CVE-2025-64505MEDIUMLIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette indexEPSS 0.2%CVE-2024-37086MEDIUMVMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine withEPSS 0.2%CVE-2026-61721HIGHFluidSynth: Heap-based buffer overrun for DLS samplesEPSS 0.2%CVE-2026-72522MEDIUMlibexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates dEPSS 0.2%CVE-2026-27692HIGHiccDEV has HBO in CIccTagTextDescription::Release()EPSS 0.2%CVE-2021-37687MEDIUMHeap OOB in TensorFlow Lite's `Gather*` implementationsEPSS 0.2%CVE-2026-3441MEDIUMBinutils: gnu binutils: information disclosure via specially crafted xcoff object fileEPSS 0.2%CVE-2026-3442MEDIUMBinutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linkerEPSS 0.2%CVE-2024-23808MEDIUMArkcompiler ets frontend has an out-of-bounds read vulnerabilityEPSS 0.2%CVE-2025-32412HIGHFuji Electric Smart Editor Out-of-bounds ReadEPSS 0.2%CVE-2026-28420MEDIUMVim has Heap-based Buffer Overflow and OOB Read in :terminalEPSS 0.2%CVE-2026-47104MEDIUMlibusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()EPSS 0.2%CVE-2025-22003MEDIUMcan: ucan: fix out of bound read in strscpy() sourceEPSS 0.2%CVE-2026-2858MEDIUMwren-lang wren Source File wren_compiler.c peekChar out-of-boundsEPSS 0.2%CVE-2025-62525HIGHOpenWrt vulnerable to local privilage escalationEPSS 0.2%CVE-2021-29547LOWHeap out of bounds in `QuantizedBatchNormWithGlobalNormalization`EPSS 0.2%CVE-2026-12033MEDIUMOut of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process toEPSS 0.2%CVE-2025-6632MEDIUMPSD File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%