Fallos del tipo CWE-125

5180 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2022-23089MEDIUMOut of bound read in elf_note_prpsinfo()EPSS 0.2%CVE-2026-13705HIGHImager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rleEPSS 0.2%CVE-2026-77237HIGHMissing type validation in xQueueAddToSet in FreeRTOS-KernelEPSS 0.2%CVE-2026-12897HIGHOut-of-bounds read in Horner Automation CscapeEPSS 0.2%CVE-2025-52938MEDIUMPotential heap-based buffer over-read vulnerability in NotepadNextEPSS 0.2%CVE-2026-52295LOWFFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavfEPSS 0.2%CVE-2026-71498MEDIUMnode-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScriptEPSS 0.2%CVE-2026-45612MEDIUMrz-libdemangle: Out of bound read in rust demanglerEPSS 0.2%CVE-2021-37651HIGHHeap buffer overflow in `FractionalAvgPoolGrad` in TensorFlowEPSS 0.2%CVE-2022-42517MEDIUMIn MiscService::DoOemSetTcsFci of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to EPSS 0.2%CVE-2022-20575MEDIUMIn read_ppmpu_info of drm_fw.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local informatioEPSS 0.2%CVE-2026-34556MEDIUMiccDEV: HBO in icAnsiToUtf8()EPSS 0.2%CVE-2026-59146HIGHData::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slotEPSS 0.2%CVE-2022-20574MEDIUMIn sec_sysmmu_info of drm_fw.c, there is a possible out of bounds read due to improper input validation. This could lead to local informatioEPSS 0.2%CVE-2026-22717LOWVMware Workstation out-of-bound read vulnerabilityEPSS 0.2%CVE-2022-40708LOWAn Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local EPSS 0.2%CVE-2026-34554MEDIUMiccDEV: HBO in CIccApplyCmmSearch::costFunc()EPSS 0.2%CVE-2025-14055LOWInteger underflow in Secure NCP hostEPSS 0.2%CVE-2024-33653HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past EPSS 0.2%CVE-2026-56788MEDIUMRTKLIB 2.4.3 - Out-of-bounds Read via Negative Array Index in getcodepriEPSS 0.2%