Falhas do tipo CWE-125

5.161 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-24182MEDIUMAn out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.EPSS 0.3%CVE-2024-20712MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability IIIEPSS 0.3%CVE-2022-26369MEDIUMOut-of-bounds read in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentialEPSS 0.3%CVE-2024-20714MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VEPSS 0.3%CVE-2024-20710MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability IEPSS 0.3%CVE-2024-20771MEDIUMBridge 2024 MOV File parsing memory corruptionEPSS 0.3%CVE-2025-4098HIGHOut-of-bounds Read in Horner Automation CscapeEPSS 0.3%CVE-2024-49529MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-20715MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VIIIEPSS 0.3%CVE-2024-20796MEDIUMAdobe Animation SWF File Parsing Memory CorruptionEPSS 0.3%CVE-2022-46440MEDIUMttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.EPSS 0.3%CVE-2026-10999MEDIUMInteger overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer procEPSS 0.3%CVE-2026-18716HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2022-34677MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause EPSS 0.3%CVE-2024-20138HIGHIn wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure witEPSS 0.3%CVE-2023-34401LOWMercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which EPSS 0.3%CVE-2026-10927HIGHOut of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potEPSS 0.3%CVE-2026-48040MEDIUMnetty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory AccessEPSS 0.3%CVE-2026-10889HIGHOut of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to poEPSS 0.3%CVE-2021-22484HIGHSome Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful exploitation of this vulnEPSS 0.3%