Falhas do tipo CWE-125

5.176 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-69617HIGHWindows Resilient File System (ReFS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69630HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-78475MEDIUMGimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loaderEPSS 0.3%CVE-2026-13890MEDIUMOut of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process EPSS 0.3%CVE-2026-82330MEDIUMGimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds checkEPSS 0.3%CVE-2026-8541MEDIUMOut of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtaEPSS 0.3%CVE-2026-8543MEDIUMOut of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage inEPSS 0.3%CVE-2026-33450LOWOut of bounds read in Secure Access MacOS clients prior to 14.50EPSS 0.3%CVE-2026-82328MEDIUMGimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette countEPSS 0.3%CVE-2024-27529HIGHwasm3 139076a contains memory leaks in Read_utf8.EPSS 0.3%CVE-2026-13975MEDIUMOut of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2026-72952HIGHWindows Spaceport.sys Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-8546MEDIUMOut of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2024-45463HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.3%CVE-2026-31885MEDIUMFreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checksEPSS 0.3%CVE-2026-20611HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 andEPSS 0.3%CVE-2025-63523MEDIUMFeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticatEPSS 0.3%CVE-2024-50268HIGHusb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd()EPSS 0.3%CVE-2026-13480LOWOut-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handlerEPSS 0.3%CVE-2024-50278HIGHdm cache: fix potential out-of-bounds access on the first resumeEPSS 0.3%