Falhas do tipo CWE-125

5.131 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-16002HIGHOut-of-bounds Read in MZ Automation lib60870EPSS 0.4%CVE-2026-84516HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.4%CVE-2026-84524MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, maEPSS 0.4%CVE-2024-40799HIGHAn out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and EPSS 0.4%CVE-2023-43843HIGHIncorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated EPSS 0.4%CVE-2022-4645MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff EPSS 0.4%CVE-2024-37005HIGHMultiple Vulnerabilities in the Autodesk AutoCAD Desktop SoftwareEPSS 0.4%CVE-2025-61043CRITICALAn out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper::GetUTF16FromUTF8 fEPSS 0.4%CVE-2025-50152HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2022-1714HIGHOut-of-bounds Read in radareorg/radare2EPSS 0.4%CVE-2023-47061MEDIUMZDI-CAN-22278: Adobe Dimension GLB File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-31714HIGHBuffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the Lua library componentEPSS 0.4%CVE-2025-55339HIGHWindows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-55639MEDIUMxrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)EPSS 0.4%CVE-2023-47078MEDIUMZDI-CAN-22249: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-25941MEDIUMFreeRDP: vuln_1_15_1 RDPGFX WIRE_TO_SURFACE_2 Out-of-Bounds ReadEPSS 0.4%CVE-2026-59189HIGHOpenEXR: Out-of-bounds read in DeepImageChannel::row() for non-zero dataWindow originEPSS 0.4%CVE-2025-1932HIGHInconsistent comparator in XSLT sorting led to out-of-bounds accessEPSS 0.4%CVE-2022-41910MEDIUMHeap out of bounds read in `QuantizeAndDequantizeV2` in TensorflowEPSS 0.4%CVE-2026-59981HIGHOpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindowEPSS 0.4%