Falhas do tipo CWE-125

5.176 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-68132LOWEVerest has out-of-bounds read in DZG_GSH01 SLIP CRC parser that can crash powermeter driverEPSS 0.3%CVE-2024-9751HIGHTungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-13820MEDIUMOut of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer processEPSS 0.3%CVE-2024-8814HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-9750HIGHTungsten Automation Power PDF PNG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-53834HIGHIn sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect bounds check. This couldEPSS 0.3%CVE-2024-9755HIGHTungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-71264LOWMumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).EPSS 0.3%CVE-2024-8812HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-10658HIGHOut-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validationEPSS 0.3%CVE-2024-8833HIGHPDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2018-9484HIGHIn l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remotEPSS 0.3%CVE-2026-73462HIGHOn affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IEPSS 0.3%CVE-2026-73761MEDIUMUnauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclosure in AOS-CXEPSS 0.3%CVE-2022-49368HIGHnet: ethernet: mtk_eth_soc: out of bounds read in mtk_hwlro_get_fdir_entry()EPSS 0.3%CVE-2026-5886MEDIUMOut of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive infoEPSS 0.3%CVE-2024-4079HIGHOut of Bounds Read Due to Missing Bounds Check in LabVIEWEPSS 0.3%CVE-2026-17028MEDIUMPower System Out-of-bounds ReadEPSS 0.3%CVE-2024-28571MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the fEPSS 0.3%CVE-2024-25392MEDIUMAn out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.EPSS 0.3%