Falhas do tipo CWE-125

5.177 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-34616MEDIUMDNG SDK | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-17770MEDIUMOut of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2026-27268MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-44281MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS VeEPSS 0.3%CVE-2026-27219MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-27270MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-57982HIGHxfrm: state: fix out-of-bounds read during lookupEPSS 0.3%CVE-2022-39156—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), EPSS 0.3%CVE-2025-32003MEDIUMOut-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, cpk 1.3.7 within RingEPSS 0.3%CVE-2025-5167MEDIUMOpen Asset Import Library Assimp LWOLoader.h GetS0 out-of-boundsEPSS 0.3%CVE-2022-39145—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), EPSS 0.3%CVE-2025-5168MEDIUMOpen Asset Import Library Assimp MDLLoader.cpp ImportUVCoordinate_3DGS_MDL345 out-of-boundsEPSS 0.3%CVE-2025-5165MEDIUMOpen Asset Import Library Assimp MDCLoader.cpp ValidateSurfaceHeader out-of-boundsEPSS 0.3%CVE-2018-9365CRITICALIn smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check. This coEPSS 0.3%CVE-2023-41051LOWDefault functions in VolatileMemory trait lack bounds checks in vm-memoryEPSS 0.3%CVE-2025-43584MEDIUMSubstance3D - Viewer | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2022-39153—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), EPSS 0.3%CVE-2025-9326HIGHFoxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-53873LOWNVIDIA CUDA toolkit for Windows contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing EPSS 0.3%CVE-2025-5169MEDIUMOpen Asset Import Library Assimp MDLLoader.cpp InternReadFile_3DGS_MDL345 out-of-boundsEPSS 0.3%