Fallos del tipo CWE-125

5180 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2026-4367MEDIUMLibxpm: libxpm: denial of service via out-of-bounds read in xpm file parsingEPSS 0.2%CVE-2022-41585HIGHThe kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.EPSS 0.2%CVE-2026-13326MEDIUMOut-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC moduleEPSS 0.2%CVE-2025-23272MEDIUMNVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially crafted JPEG file. EPSS 0.2%CVE-2026-5713MEDIUMOut-of-bounds read/write during remote profiling and asyncio process introspection when connecting to malicious targetEPSS 0.2%CVE-2026-102714HIGH`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whosEPSS 0.2%CVE-2026-65349MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8,EPSS 0.2%CVE-2026-57253MEDIUMFoxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2026-88054MEDIUMTesseract: Denial of service via empty-stack dereference in Plumbing/Series at model loadEPSS 0.2%CVE-2026-102726MEDIUMUnbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds ReadEPSS 0.2%CVE-2026-57241MEDIUMFoxit PDF Editor/Reader Page Out-of-bounds Read VulnerabilityEPSS 0.2%CVE-2021-41210HIGHHeap OOB read in `tf.raw_ops.SparseCountSparseOutput`EPSS 0.2%CVE-2026-57243MEDIUMFoxit PDF Editor/Reader Page Out-of-bounds Read VulnerabilityEPSS 0.2%CVE-2026-45258HIGHMultiple vulnerabilities in the sound(4) mmap pathEPSS 0.2%CVE-2026-102725MEDIUMOut-of-bounds Read from Unvalidated MSRP Attribute List LengthEPSS 0.2%CVE-2026-102720MEDIUMA DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received EPSS 0.2%CVE-2025-39901HIGHi40e: remove read access to debugfs filesEPSS 0.2%CVE-2026-33451HIGHArbitrary read/write vulnerability in Windows clients prior to 14.50EPSS 0.2%CVE-2026-42494MEDIUMbuffer overruns in libfsimage iso9660 handlingEPSS 0.2%CVE-2026-57257MEDIUMSecurity vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB ReadEPSS 0.2%