Falhas do tipo CWE-125

5.159 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2024-41126HIGHOut-of-bounds read when decoding SNMP messages in Contiki-NGEPSS 0.3%CVE-2026-41677LOWrust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized lengthEPSS 0.3%CVE-2026-9122MEDIUMOut of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive informatEPSS 0.3%CVE-2023-38213MEDIUMZDI-CAN-21094: Adobe Dimension GLB File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-28692MEDIUMImageMagick has a heap buffer over-read via 32-bit integer overflow in MAT decoderEPSS 0.3%CVE-2022-4144MEDIUMAn out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of thEPSS 0.3%CVE-2026-89156LOWPCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.EPSS 0.3%CVE-2026-13873MEDIUMOut of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fEPSS 0.3%CVE-2025-21124MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-9996MEDIUMOut of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive inforEPSS 0.3%CVE-2024-41125HIGHOut-of-bounds read in SNMP when decoding a string in Contiki-NGEPSS 0.3%CVE-2022-31617HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabiEPSS 0.3%CVE-2026-27284HIGHInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-27287HIGHInCopy | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-49511MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-49510MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2025-54325MEDIUMAn issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W92EPSS 0.3%CVE-2026-27269HIGHPremiere Pro | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-49512MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-13858MEDIUMOut of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fEPSS 0.3%