Falhas do tipo CWE-125

5.134 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-51602MEDIUMmmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMEPSS 0.4%CVE-2026-69345MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-27163MEDIUMAcrobat Reader | Out-of-bounds Read (CWE-125)EPSS 0.4%CVE-2026-69367MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-69308MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-68881MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-69303MEDIUMPush Message Routing Service Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-5873HIGHOut of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2024-51562MEDIUMbhyve(8) nvme_opc_get_log_page buffer over-readEPSS 0.4%CVE-2023-43692HIGHAn issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). Out-of-bound reads in striEPSS 0.4%CVE-2025-53859MEDIUMNGINX ngx_mail_smtp_module vulnerabilityEPSS 0.4%CVE-2025-55086MEDIUMIn NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked indEPSS 0.4%CVE-2026-44041MEDIUMUltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminatedEPSS 0.4%CVE-2025-47112MEDIUMAcrobat Reader | Out-of-bounds Read (CWE-125)EPSS 0.4%CVE-2026-9928HIGHOut of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crEPSS 0.4%CVE-2026-82072HIGHOut of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via EPSS 0.4%CVE-2026-15903HIGHOut of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.4%CVE-2026-78978HIGHOut of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitraryEPSS 0.4%CVE-2026-87440HIGHOut of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox vEPSS 0.4%CVE-2024-29948LOWThere is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending sEPSS 0.4%