Falhas do tipo CWE-125

5.130 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-54988MEDIUMMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-64098LOWFastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is enabledEPSS 0.5%CVE-2023-38105LOWFoxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-51567LOWKofax Power PDF OXPS File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-51564LOWKofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-38106LOWFoxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-5735HIGHMemory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2EPSS 0.5%CVE-2026-33822MEDIUMMicrosoft Word Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-5512LOWKofax Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-39483LOWPDF-XChange Editor J2K File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-62351HIGHTDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in transDecompressMsgEPSS 0.5%CVE-2026-54592HIGHOj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested InputEPSS 0.5%CVE-2026-3631HIGHBuffer Over-read DoS Vulnerability in COMMGR2EPSS 0.5%CVE-2026-77556HIGHA malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to exeEPSS 0.5%CVE-2026-26008HIGHEVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferModesEPSS 0.5%CVE-2026-77558HIGHA malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to exeEPSS 0.5%CVE-2026-53704HIGHGstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo metadata parserEPSS 0.5%CVE-2026-53703HIGHGstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio stream header parserEPSS 0.5%CVE-2026-63033MEDIUMMZ Automation lib60870 Out-of-bounds ReadEPSS 0.5%CVE-2024-5268MEDIUMSonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%