Falhas do tipo CWE-125

5.126 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2022-38440HIGHAdobe Dimension SKP File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-38441HIGHAdobe Dimension GLB File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-29309MEDIUM[FG-VD-23-003] Adobe InDesign 2023 Out-of-Bound Read Vulnerability NotificationEPSS 0.5%CVE-2023-29315MEDIUM[FG-VD-23-008] Adobe InDesign 2023 Out-of-Bound Read Vulnerability VI NotificationEPSS 0.5%CVE-2022-41895MEDIUM`MirrorPadGrad` heap out of bounds read in TensorflowEPSS 0.5%CVE-2026-50811MEDIUMAn out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truEPSS 0.5%CVE-2024-54937MEDIUMA Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files EPSS 0.5%CVE-2024-30356LOWFoxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2022-41897MEDIUM`FractionalMaxPoolGrad` Heap out of bounds read in TensorflowEPSS 0.5%CVE-2024-30340LOWFoxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2022-48479CRITICALThe facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability maEPSS 0.5%CVE-2022-44502MEDIUMAdobe Illustrator Font Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-55898MEDIUMMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-3407MEDIUMNothings stb stbhw_build_tileset_from_image out-of-boundsEPSS 0.5%CVE-2024-52876HIGHHoly Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remoteEPSS 0.5%CVE-2022-38412HIGHAdobe Animate SVG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-23333MEDIUMNVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-ofEPSS 0.5%CVE-2026-25898MEDIUMImagemagick Has Global Buffer Overflow (OOB Read) via Negative Pixel Index in UIL and XPM WriterEPSS 0.5%CVE-2026-82618MEDIUMSysterel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matrix_on_string_array out-of-boundsEPSS 0.5%CVE-2026-87961HIGHESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed Length Parameter in read_ID3_HeaderEPSS 0.5%