Falhas do tipo CWE-125

5.179 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-54203MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-40134MEDIUMAn information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access andEPSS 0.2%CVE-2025-54200MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54205MEDIUMSubstance3D - Sampler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54193MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54202MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-65969MEDIUMOpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGVEPSS 0.2%CVE-2025-54195MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-40936HIGHA vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2EPSS 0.2%CVE-2025-54198MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54189MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2021-26254MEDIUMOut of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable denEPSS 0.2%CVE-2026-3391MEDIUMFascinatedBox lily lily_emitter.c clear_storages out-of-boundsEPSS 0.2%CVE-2024-26275HIGHA vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All vEPSS 0.2%CVE-2025-54233MEDIUMAdobe Framemaker | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2021-26950MEDIUMOut of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow EPSS 0.2%CVE-2026-3390MEDIUMFascinatedBox lily Error Reporting lily_build_error.c patch_line_end out-of-boundsEPSS 0.2%CVE-2022-49740HIGHwifi: brcmfmac: Check the count value of channel spec to prevent out-of-bounds readsEPSS 0.2%CVE-2026-86137LOWIn libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.EPSS 0.2%CVE-2022-49738HIGHf2fs: fix to do sanity check on i_extra_isize in is_alive()EPSS 0.2%