Falhas do tipo CWE-125

5.159 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-86714MEDIUMPX4 Autopilot through 1.17.0 Stack Buffer Over-read via netmanEPSS 0.3%CVE-2024-39393HIGHAdobe Indesign 2024 PCT File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-25863HIGHAdobe Substance 3D Stager USDC File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-42387LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.3%CVE-2026-37535HIGHopenxc/isotp-c thru commit 5a5d19245f65189202719321facd49ce6f5d46ac (2021-08-09) contains an out-of-bounds read in the ISO-TP Single Frame rEPSS 0.3%CVE-2025-24149MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS SeqEPSS 0.3%CVE-2020-35535—In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when proEPSS 0.3%CVE-2026-45615HIGHmouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OER PayloadEPSS 0.3%CVE-2025-55092MEDIUMPotential out of bound read in _nx_ipv4_option_process()EPSS 0.3%CVE-2025-52512HIGHAn issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in out-of-bounds memEPSS 0.3%CVE-2026-3894CRITICALOut-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.3%CVE-2026-4460HIGHOut of bounds read in Skia in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via a EPSS 0.3%CVE-2026-4440HIGHOut of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write viaEPSS 0.3%CVE-2026-17701CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromEPSS 0.3%CVE-2026-64685MEDIUMImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file checkEPSS 0.3%CVE-2026-4462HIGHOut of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via aEPSS 0.3%CVE-2026-84968MEDIUMHeap out-of-bounds read via corrupt nested BSON in field path error messageEPSS 0.3%CVE-2026-17423HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2026-45358MEDIUMImageMagick: Out-of-Bounds Read of a single byte in meta encoderEPSS 0.3%CVE-2022-28183HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can caEPSS 0.3%