Fallos del tipo CWE-125

5180 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2026-43738MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS GoEPSS 0.2%CVE-2026-43747HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TEPSS 0.2%CVE-2022-20523MEDIUMIn IncFs_GetFilledRangesStartingFrom of incfs.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to EPSS 0.2%CVE-2025-65088HIGHOut-of-bounds read in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt ShareEPSS 0.2%CVE-2025-20101MEDIUMOut-of-bounds read for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable information disclosure or denialEPSS 0.2%CVE-2026-39956MEDIUMjq: Missing runtime type checks for _strindices lead to crash and limited memory disclosureEPSS 0.2%CVE-2024-47940HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of boundEPSS 0.2%CVE-2024-27380MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2026-64776MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An EPSS 0.2%CVE-2024-47941HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of boundEPSS 0.2%CVE-2024-27381MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2024-22273HIGHThe storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access tEPSS 0.2%CVE-2026-58087HIGHHeap out-of-bounds access in semctl(2)EPSS 0.2%CVE-2025-65087HIGHOut-of-bounds read in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt ShareEPSS 0.2%CVE-2026-64692HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOEPSS 0.2%CVE-2023-53222HIGHjfs: jfs_dmap: Validate db_l2nbperpage while mountingEPSS 0.2%CVE-2026-62291MEDIUMlibheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensionsEPSS 0.2%CVE-2026-40253MEDIUMopenCryptoki: Memory safety vulnerabilities in BER/DER decoders in asn1.cEPSS 0.2%CVE-2026-20489MEDIUMIn display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a maliEPSS 0.2%CVE-2025-41392HIGHAshlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share Out-of-bounds ReadEPSS 0.2%