Falhas do tipo CWE-125

5.159 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-33982HIGHFreeRDP: Persistent Cache Allocator Mismatch - Heap OOB ReadEPSS 0.3%CVE-2020-1824LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2021-36060MEDIUMAdobe Media Encoder MPEG File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2025-46316MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS TahoeEPSS 0.3%CVE-2026-41034MEDIUMONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and othEPSS 0.3%CVE-2026-69549HIGHVirtual Hard Disk (VHD) Miniport Driver Elevation of Privilege VulernabilityEPSS 0.3%CVE-2026-35217MEDIUMNanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds ReadEPSS 0.3%CVE-2026-24189HIGHNVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliEPSS 0.3%CVE-2026-44067LOWEA header parsing heap over-readEPSS 0.3%CVE-2025-43265MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS SequEPSS 0.3%CVE-2023-48638MEDIUMAdobe Substance 3D Designer 13.0.2 build 6942 Vulnerability IIIEPSS 0.3%CVE-2026-9121HIGHOut of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.3%CVE-2026-15114HIGHOut of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corrupEPSS 0.3%CVE-2023-48636MEDIUMAdobe Substance 3D Designer 13.0.2 build 6942 Vulnerability IVEPSS 0.3%CVE-2023-47080MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VIEPSS 0.3%CVE-2023-51559LOWFoxit PDF Reader Doc Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-7354HIGHOut of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox esEPSS 0.3%CVE-2023-47081MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability IIEPSS 0.3%CVE-2026-79241MEDIUMOut of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandboxEPSS 0.3%CVE-2022-47520HIGHAn issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in theEPSS 0.3%