Falhas do tipo CWE-125

5.179 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2024-3933MEDIUMEclipse Open J9 With -Xgc:concurrentScavenge on IBM Z, could write/read outside of a bufferEPSS 0.2%CVE-2021-47586MEDIUMnet: stmmac: dwmac-rk: fix oob read in rk_gmac_setupEPSS 0.2%CVE-2021-41224HIGH`SparseFillEmptyRows` heap OOB readEPSS 0.2%CVE-2024-7670HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.2%CVE-2021-29560LOWHeap buffer overflow in `RaggedTensorToTensor`EPSS 0.2%CVE-2021-41212HIGHHeap OOB read in `tf.ragged.cross`EPSS 0.2%CVE-2025-15412MEDIUMWebAssembly wabt wasm-decompile VarName out-of-boundsEPSS 0.2%CVE-2024-8588HIGHAutodesk AutoCAD SLDPRT File Parsing Out-Of-Bounds Read VulnerabilityEPSS 0.2%CVE-2024-44134MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to reEPSS 0.2%CVE-2021-41211HIGHHeap OOB read in shape inference for `QuantizeV2`EPSS 0.2%CVE-2024-9827HIGHAutodesk AutoCAD ACTranslators CATPART File Parsing Out-Of-Bounds Read VulnerabilityEPSS 0.2%CVE-2024-8589HIGHAutodesk AutoCAD SLDPRT File Parsing Out-Of-Bounds Read VulnerabilityEPSS 0.2%CVE-2021-41223HIGHHeap OOB read in `FusedBatchNorm` kernelsEPSS 0.2%CVE-2021-41226HIGHHeap OOB read in `SparseBinCount`EPSS 0.2%CVE-2026-16782MEDIUMSVG File Parsing Out-of-Bounds Read Vulnerability in Autodesk 3ds MaxEPSS 0.2%CVE-2026-20620HIGHAn out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, EPSS 0.2%CVE-2024-50123HIGHbpf: Add the missing BPF_LINK_TYPE invocation for sockmapEPSS 0.2%CVE-2023-24475MEDIUMOut of bounds read in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosuEPSS 0.2%CVE-2024-23802HIGHA vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (AllEPSS 0.2%CVE-2024-47021MEDIUMIn sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to reEPSS 0.2%