Falhas do tipo CWE-125

5.159 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-10979MEDIUMOut of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information frEPSS 0.3%CVE-2022-43282HIGHwasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.EPSS 0.3%CVE-2024-35423HIGHvmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.EPSS 0.3%CVE-2024-20129HIGHIn Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no addiEPSS 0.3%CVE-2025-7698MEDIUMOut-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic PlEPSS 0.3%CVE-2026-5292HIGHOut of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read vEPSS 0.3%CVE-2024-20128HIGHIn Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no addiEPSS 0.3%CVE-2024-20127HIGHIn Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no addiEPSS 0.3%CVE-2025-0437MEDIUMOut of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.3%CVE-2026-12298MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2026-44518MEDIUMliboqs: XMSS Buffer Overread BugEPSS 0.3%CVE-2022-42901HIGHBentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when opening crafted XMTEPSS 0.3%CVE-2025-53051LOWVulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. EasilyEPSS 0.3%CVE-2026-66759HIGHGimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns imagesEPSS 0.3%CVE-2023-4721MEDIUMOut-of-bounds Read in gpac/gpacEPSS 0.3%CVE-2024-22957MEDIUMswftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the function dict_do_lookup in swftools/lib/q.c:1190.EPSS 0.3%CVE-2026-24812CRITICALAn improper pointer arithmetic in root-project/root at builtins/zlib/inftrees.cEPSS 0.3%CVE-2026-46344MEDIUMliboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter mismatch (xmss_commons.c:194)EPSS 0.3%CVE-2024-49527MEDIUMAnimate | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-9895HIGHOut of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potEPSS 0.3%