Falhas do tipo CWE-125

5.131 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-85090MEDIUMFreeRDP before 3.31.0 Heap Out-of-Bounds Read via AVC444EPSS 0.4%CVE-2023-42072LOWPDF-XChange Editor JPC File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-6610HIGHKernel: oob access in smb2_dump_detailEPSS 0.4%CVE-2023-42081LOWPDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-14647MEDIUMonnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-boundsEPSS 0.4%CVE-2023-42049LOWPDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-48682MEDIUMFastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, aftEPSS 0.4%CVE-2023-42066LOWPDF-XChange Editor J2K File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-20948HIGHIn dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remoEPSS 0.4%CVE-2026-84449LOWlibheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGVEPSS 0.4%CVE-2026-84543HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, EPSS 0.4%CVE-2023-29383—In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is noEPSS 0.4%CVE-2026-45382MEDIUMlibde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometryEPSS 0.4%CVE-2018-16885MEDIUMA flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buEPSS 0.4%CVE-2021-39252MEDIUMA crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.EPSS 0.4%CVE-2026-45383MEDIUMlibde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18EPSS 0.4%CVE-2026-30802HIGHOut-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.EPSS 0.4%CVE-2022-25749HIGHTransient Denial-of-Service in WLAN due to buffer over-read while parsing MDNS frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.4%CVE-2026-57235MEDIUMNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`EPSS 0.4%CVE-2023-39496HIGHPDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.4%