Falhas do tipo CWE-125

5.179 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-61798HIGHDimension | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-40338MEDIUMlibgphoto2 has OOB read in ptp_unpack_Sony_DPD() enumeration count parsing in ptp-pack.cEPSS 0.2%CVE-2025-7265HIGHIrfanView CADImage Plugin CGM File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-34961MEDIUMbarebox ext4 Extent Parsing Out-of-Bounds ReadEPSS 0.2%CVE-2026-84270MEDIUMGvfs: mtp: out-of-bounds read in do_read()EPSS 0.2%CVE-2025-1659HIGHDWFX File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2018-9429MEDIUMIn buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to informatioEPSS 0.2%CVE-2024-50259MEDIUMnetdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()EPSS 0.2%CVE-2025-1658HIGHDWFX File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2025-43551MEDIUMSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-49525MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54262HIGHSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-29939MEDIUMllvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv:EPSS 0.2%CVE-2023-30795HIGHA vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4), Parasolid V34.0 (All versions < EPSS 0.2%CVE-2025-30313MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2017-13320MEDIUMIn impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with EPSS 0.2%CVE-2023-24556HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2022-31612HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a loEPSS 0.2%CVE-2023-24552HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2026-3285MEDIUMberry-lang berry be_lexer.c scan_string out-of-boundsEPSS 0.2%