Falhas do tipo CWE-125

5.136 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-48816HIGHHID Class Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-47996HIGHWindows MBT Transport Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-67306MEDIUMFreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLEEPSS 0.4%CVE-2026-45681MEDIUMOpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB sizeEPSS 0.4%CVE-2024-27345LOWKofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-45608MEDIUMWindows DHCP Client Information Disclosure VulnerabilityEPSS 0.4%CVE-2022-42402HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2024-5307LOWKofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-48635MEDIUMZDI-CAN-22174: Adobe After Effects AEP File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-7425MEDIUMOut-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCPEPSS 0.4%CVE-2026-50735MEDIUMpglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copyinEPSS 0.4%CVE-2025-37178MEDIUMOut-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating SystemEPSS 0.4%CVE-2026-10848HIGHOut-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)EPSS 0.4%CVE-2022-41883MEDIUMOut of bounds segmentation fault due to unequal op inputs in TensorflowEPSS 0.4%CVE-2026-32738MEDIUMlibheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunkEPSS 0.4%CVE-2026-42799HIGHOut-of-bounds read in ulpEPSS 0.4%CVE-2024-24452MEDIUMAn invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attacEPSS 0.4%CVE-2026-28532MEDIUMFRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser FunctionsEPSS 0.4%CVE-2023-36629MEDIUMThe ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.EPSS 0.4%CVE-2026-12087CRITICALSocket versions before 2.041 for Perl have an out-of-bounds heap readEPSS 0.4%