Falhas do tipo CWE-125

5.179 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-21322HIGHAfter Effects | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-21324HIGHAfter Effects | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-39188HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-27401HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of EPSS 0.2%CVE-2023-27402HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of EPSS 0.2%CVE-2026-56374MEDIUMImageMagick - Heap Buffer Overflow in FTXT Encoder via format ParameterEPSS 0.2%CVE-2023-27405HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of EPSS 0.2%CVE-2024-26702MEDIUMiio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRCEPSS 0.2%CVE-2025-21742HIGHusbnet: ipheth: use static NDP16 location in URBEPSS 0.2%CVE-2025-47754HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!Conv_Macro_Data function. Opening specially crafted V7 oEPSS 0.2%CVE-2024-50227HIGHthunderbolt: Fix KASAN reported stack out-of-bounds read in tb_retimer_scan()EPSS 0.2%CVE-2026-12303MEDIUMInformation disclosure due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.2%CVE-2025-47756HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CGamenDataRom::set_mr400_strc function. Opening speciallEPSS 0.2%CVE-2025-47753HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CDrawSLine::GetRectArea function. Opening specially crafEPSS 0.2%CVE-2025-21741HIGHusbnet: ipheth: fix DPE OoB readEPSS 0.2%CVE-2026-21278MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-47757HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6MemInIF.dll!set_plc_type_default function. Opening specially crafEPSS 0.2%CVE-2025-32100MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.2%CVE-2026-2869MEDIUMjanet-lang janet handleattr specials.c janetc_varset out-of-boundsEPSS 0.2%CVE-2026-8084MEDIUMOSGeo gdal HDF-EOS Grid File SWapi.c memmove out-of-boundsEPSS 0.2%