Fallos del tipo CWE-125

5182 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2026-31912MEDIUMOOBR in libpcap before 1.10.7EPSS 0.1%CVE-2026-77797LOWVelociraptor Prefetch parser out of boundsEPSS 0.1%CVE-2026-79616LOWOut-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt QuickEPSS 0.1%CVE-2025-29937MEDIUMAn out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory loEPSS 0.1%CVE-2026-18458MEDIUMOut-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.1%CVE-2026-102757HIGHAn unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode,EPSS 0.1%CVE-2025-27940MEDIUMOut-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Software side chEPSS 0.1%CVE-2026-11389MEDIUMOut-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.1%CVE-2026-18626MEDIUMOut-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.1%CVE-2018-9464HIGHIn multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalatioEPSS 0.1%CVE-2024-20093MEDIUMIn vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System eEPSS 0.1%CVE-2022-27832MEDIUMImproper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a craftedEPSS 0.1%CVE-2026-10305MEDIUMOut-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462EPSS 0.1%CVE-2025-36918HIGHIn aoc_service_read_message of aoc_ipc_core.c, there is a possible out of bounds read due to improper input validation. This could lead to lEPSS 0.1%CVE-2023-20840MEDIUMIn imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of prEPSS 0.1%CVE-2023-20848MEDIUMIn imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privileEPSS 0.1%CVE-2026-94284MEDIUMOut-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parserEPSS 0.1%CVE-2026-0135HIGHIn Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no additional EPSS 0.1%CVE-2023-42726MEDIUMIn TeleService, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with SystemEPSS 0.1%CVE-2024-20107MEDIUMIn da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additioEPSS 0.1%