Falhas do tipo CWE-125

5.179 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2024-27860MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An application may be able to read restricteEPSS 0.2%CVE-2024-39396MEDIUMAdobe Indesign 2024 PCX File Parsing Out Of Bound ReadEPSS 0.2%CVE-2025-1400LOWOut-of-bounds Read in libplctag libraryEPSS 0.2%CVE-2023-25008HIGHA malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result iEPSS 0.2%CVE-2026-34776MEDIUMElectron: Out-of-bounds read in second-instance IPC on macOS and LinuxEPSS 0.2%CVE-2023-0621HIGHCVE-2023-0621EPSS 0.2%CVE-2025-1399LOWOut-of-bounds Read in libplctag libraryEPSS 0.2%CVE-2025-24448MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-101205MEDIUMFastStone Image Viewer PCX Decoder out-of-boundsEPSS 0.2%CVE-2025-1431HIGHSLDPRT File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2024-52613MEDIUMA heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) via a crafteEPSS 0.2%CVE-2025-1652HIGHMODEL File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2026-101204MEDIUMFastStone Image Viewer TGA Image FSViewer.exe out-of-boundsEPSS 0.2%CVE-2025-1433HIGHMODEL File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2022-41613HIGHBentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when parsing DGN files, wEPSS 0.2%CVE-2026-79004LOWOut of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to reEPSS 0.2%CVE-2025-21920HIGHvlan: enforce underlying device typeEPSS 0.2%CVE-2025-21789HIGHLoongArch: csum: Fix OoB access in IP checksum code for negative lengthsEPSS 0.2%CVE-2026-85052LOWOut of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2026-0956HIGHOut-Of-Bounds Read in Digilent DASYLabEPSS 0.2%