Falhas do tipo CWE-125

5.176 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2024-25392MEDIUMAn out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.EPSS 0.3%CVE-2020-36602MEDIUMThere is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and EPSS 0.3%CVE-2026-11077HIGHBad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted EPSS 0.3%CVE-2026-50491HIGHCode Integrity DLL (ci.dll) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-32055HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past EPSS 0.3%CVE-2024-32635HIGHA vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), TeamceEPSS 0.3%CVE-2025-26441MEDIUMIn add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informationEPSS 0.3%CVE-2022-43043MEDIUMGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTimeOffset at /bifs/fielEPSS 0.3%CVE-2025-2231HIGHPDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-53333HIGHnetfilter: conntrack: dccp: copy entire header to stack buffer, not just basic oneEPSS 0.3%CVE-2024-52998MEDIUMSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-75369HIGHAn out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit EPSS 0.3%CVE-2025-11840MEDIUMGNU Binutils ldmisc.c vfinfo out-of-boundsEPSS 0.3%CVE-2026-9913MEDIUMInappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform out of boundEPSS 0.3%CVE-2026-44064HIGHASP session ID out-of-bounds accessEPSS 0.3%CVE-2022-20604MEDIUMIn SAECOMM_SetDcnIdForPlmn of SAECOMM_DbManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead EPSS 0.3%CVE-2025-10883HIGHCATPRODUCT File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.3%CVE-2025-3160MEDIUMOpen Asset Import Library Assimp File SceneCombiner.cpp AddNodeHashes out-of-boundsEPSS 0.3%CVE-2026-54592HIGHOj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested InputEPSS 0.3%CVE-2025-5204MEDIUMOpen Asset Import Library Assimp MDLMaterialLoader.cpp ParseSkinLump_3DGS_MDL7 out-of-boundsEPSS 0.3%