Falhas do tipo CWE-125

5.179 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2024-47453MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-47436MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-41861MEDIUMAdobe Substance 3D Sampler Memory Corruption Out-of-Bounds-READ Vulnerability I, when parsing PSD fileEPSS 0.2%CVE-2024-45145MEDIUMLightroom Desktop | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-11111HIGHOut of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a EPSS 0.2%CVE-2024-47455MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-50247HIGHfs/ntfs3: Check if more than chunk-size bytes are writtenEPSS 0.2%CVE-2024-56721HIGHx86/CPU/AMD: Terminate the erratum_1386_microcode arrayEPSS 0.2%CVE-2024-30283MEDIUMAdobe FrameMaker ICO File Parsing Heap Memory CorruptionEPSS 0.2%CVE-2024-41862MEDIUMAdobe Substance 3D Sampler Memory Corruption Out-of-Bounds-READ Vulnerability II, when parsing PSD fileEPSS 0.2%CVE-2024-41860MEDIUMAdobe Substance 3D Sampler Memory Corruption Vulnerability I, when parsing PSD fileEPSS 0.2%CVE-2024-47435MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-11920MEDIUMInappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memorEPSS 0.2%CVE-2024-50208HIGHRDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pagesEPSS 0.2%CVE-2023-31278HIGHHorner Automation Cscape Out-of-bounds ReadEPSS 0.2%CVE-2023-32289HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead tEPSS 0.2%CVE-2022-21133MEDIUMOut-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable EPSS 0.2%CVE-2024-50158HIGHRDMA/bnxt_re: Fix out of bound checkEPSS 0.2%CVE-2023-32281HIGH The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to aEPSS 0.2%CVE-2024-20722MEDIUMAdobe Substance 3D Painter v9.0.1Build2822 OOBR Vulnerability IIIEPSS 0.2%