Falhas do tipo CWE-125

5.177 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-5168MEDIUMOpen Asset Import Library Assimp MDLLoader.cpp ImportUVCoordinate_3DGS_MDL345 out-of-boundsEPSS 0.3%CVE-2025-24092MEDIUMThis issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able tEPSS 0.3%CVE-2026-17550MEDIUMDWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCADEPSS 0.3%CVE-2020-1823LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2020-1822LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2026-12548MEDIUMLibsoup: heap out-of-bounds read in libsoup due to integer truncationEPSS 0.3%CVE-2024-49197MEDIUMAn issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W93EPSS 0.3%CVE-2026-28527LOWBlueKitchen BTstack < 1.8.1 AVRCP Controller GET_PLAYER_APPLICATION_SETTING_*_TEXT Handlers OOB ReadEPSS 0.3%CVE-2020-1819LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2023-42982MEDIUMProcessing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was adEPSS 0.3%CVE-2020-1820LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2020-1818LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2022-21226MEDIUMOut-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable EPSS 0.3%CVE-2020-1821LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2025-66037LOWOpenSC: Out of Bounds vulnerabilityEPSS 0.3%CVE-2023-0969LOWGlobal read overflow in Z/IP GatewayEPSS 0.3%CVE-2023-27854HIGHRockwell Automation Arena® Simulation Out of Bounds Read VulnerabilityEPSS 0.3%CVE-2026-102721MEDIUMA TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive patEPSS 0.3%CVE-2026-102712HIGHOn the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against theEPSS 0.3%CVE-2026-0127MEDIUMIn NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This coEPSS 0.3%