Falhas do tipo CWE-125

5.130 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2024-0107HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-oEPSS 0.5%CVE-2026-64784MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7EPSS 0.5%CVE-2025-55087MEDIUMIn NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by aEPSS 0.5%CVE-2025-36521HIGHMicroDicom DICOM Viewer Out-of-bounds ReadEPSS 0.5%CVE-2025-27891CRITICALAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.5%CVE-2026-31965MEDIUMHTSlib CRAM reader has out-of-bounds reads due to improper validation of inputEPSS 0.5%CVE-2026-50278MEDIUMiccDEV: CIccEmbedIO::Read8() size_t underflowEPSS 0.5%CVE-2025-4082MEDIUMWebGL shader attribute memory corruption in Thunderbird for macOSEPSS 0.5%CVE-2026-63409HIGHDeskflow: Odd-length DSOP options vector causes out-of-bounds read in Deskflow clientEPSS 0.5%CVE-2023-42088HIGHPDF-XChange Editor JPG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42058HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-43909HIGHOpenImageIO: Signed integer overflow in SwapRGBABytes loop index leads to out-of-bounds read/write in DPX ABGR decoderEPSS 0.5%CVE-2024-53004MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.5%CVE-2021-3588LOWmemory contents disclosure in cli_feat_read_cbEPSS 0.4%CVE-2025-57812LOW[BIGSLEEP-434612419] CUPS-Filters has heap-buffer-overflow write in `cfImageLut()`EPSS 0.4%CVE-2026-60065MEDIUMNGINX Plus ngx_stream_mqtt_filter_module vulnerabilityEPSS 0.4%CVE-2024-40630MEDIUMHEIF Heap OOB Read in OpenImageIOEPSS 0.4%CVE-2026-16853MEDIUMIBM i is Affected By Multiple Vulnerabilities in NetServerEPSS 0.4%CVE-2021-31431MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An EPSS 0.4%CVE-2021-31430MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An EPSS 0.4%