Falhas do tipo CWE-125

5.130 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-55031HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-81957HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-38984HIGHThe HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability EPSS 0.5%CVE-2026-63515HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-38998HIGHThe HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability EPSS 0.5%CVE-2026-64909HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-40360HIGHMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-44820HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-38981HIGHThe HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.EPSS 0.5%CVE-2026-58609HIGHWindows Graphics Component Remote Code Execution VulnerabilityEPSS 0.5%CVE-2021-46840CRITICALThe HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerabilitEPSS 0.5%CVE-2026-55058HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-68814HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-55044HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-50388HIGHWindows NTFS Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-0207HIGHOut-of-bounds Read in WiresharkEPSS 0.5%CVE-2026-81956HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-68793HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.5%CVE-2021-46839CRITICALThe HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause maliciEPSS 0.5%CVE-2024-0116MEDIUMNVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing a shared memory regiEPSS 0.5%