Fallos del tipo CWE-125

5181 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2025-9032HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed PE fileEPSS 0.1%CVE-2026-56136MEDIUMIn NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly EPSS 0.1%CVE-2025-9033HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 3)EPSS 0.1%CVE-2026-19086LOWIBM i is Affected By Multiple Vulnerabilities in PASE [, ]EPSS 0.1%CVE-2022-25665MEDIUMInformation disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon MobileEPSS 0.1%CVE-2026-75147MEDIUMFFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.cEPSS 0.1%CVE-2026-10267MEDIUMjanet-lang janet debug.c doframe out-of-boundsEPSS 0.1%CVE-2025-41278HIGHNozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackEPSS 0.1%CVE-2026-49314HIGHOOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availabiliEPSS 0.1%CVE-2022-39130MEDIUMIn face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in EPSS 0.1%CVE-2026-20751HIGHOut-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers EPSS 0.1%CVE-2026-20518MEDIUMIn geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if aEPSS 0.1%CVE-2022-42774MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2024-27223MEDIUMIn EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check.EPSS 0.1%CVE-2026-0106CRITICALIn vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%CVE-2022-42773MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-102567MEDIUMCTranslate2 before 4.8.1 Out-of-Bounds Read via Model DeserializationEPSS 0.1%CVE-2022-42761MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2023-43694MEDIUMAn issue was discovered in Malwarebytes 4.6.14.326 and before and 5.1.5.116 and before (and Nebula 2020-10-21 and later). An Out of bounds rEPSS 0.1%CVE-2026-88835MEDIUMBusybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packagesEPSS 0.1%