Falhas do tipo CWE-125

5.130 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2021-31431MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An EPSS 0.4%CVE-2021-31432MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An EPSS 0.4%CVE-2026-2443MEDIUMLibsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosureEPSS 0.4%CVE-2022-46317HIGHThe power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect system availaEPSS 0.4%CVE-2023-42045HIGHPDF-XChange Editor J2K File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-42055HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-55045HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-42063HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-42044HIGHPDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-42060HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-39775MEDIUMNet Manager has an out-of-bounds read permission bypass vulnerabilityEPSS 0.4%CVE-2023-42042HIGHPDF-XChange Editor App Object Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-42057HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-42064HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-28832HIGHAdobe InDesign Font Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-43916HIGHpam_authnft: Heap buffer overflow in NETLINK_SOCK_DIAG reply walkerEPSS 0.4%CVE-2026-20346HIGHClamAV PDF File Format Processing Memory Corruption VulnerabilityEPSS 0.4%CVE-2026-24818MEDIUMA heap-based buffer over-read that might affect a system that compiles untrusted Lua code in praydog/UEVREPSS 0.4%CVE-2026-65918HIGHPyTorch torchvision GIF Decoder Out-of-bounds Heap ReadEPSS 0.4%CVE-2026-55777MEDIUMGoAccess: Out-of-bounds heap read in parse_ios() via crafted User-Agent leads to remote crash/DoSEPSS 0.4%