Falhas do tipo CWE-125

5.180 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-0130MEDIUMIn RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information dEPSS 0.2%CVE-2022-21239MEDIUMOut-of-bounds read in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentiallyEPSS 0.2%CVE-2026-30986MEDIUMiccDEV has a heap-based buffer overflow write in CIccCLUT::Interp3d()EPSS 0.2%CVE-2026-21302MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-21308MEDIUMSubstance3D - Designer | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-81879MEDIUMradare2: Heap out-of-bounds read in radare2 ELF PN_XNUM handlingEPSS 0.2%CVE-2024-41908HIGHA vulnerability has been identified in NX (All versions < V2406.3000). The affected applications contains an out of bounds read vulnerabilitEPSS 0.2%CVE-2023-42943MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14. An app may be abEPSS 0.2%CVE-2022-20557MEDIUMIn MessageQueueBase of MessageQueueBase.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local esEPSS 0.2%CVE-2021-37679HIGHHeap OOB in nested `tf.map_fn` with `RaggedTensor`s in TensorFlowEPSS 0.2%CVE-2022-20563MEDIUMIn TBD of ufdt_convert, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of privilege wiEPSS 0.2%CVE-2024-44199HIGHAn out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause unEPSS 0.2%CVE-2026-40026MEDIUMSleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds ReadEPSS 0.2%CVE-2026-55093MEDIUMtract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model loadEPSS 0.2%CVE-2021-46772LOWInsufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the strucEPSS 0.2%CVE-2026-65979MEDIUMOpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN)EPSS 0.2%CVE-2026-19028MEDIUMHDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds readEPSS 0.2%CVE-2025-20688MEDIUMIn wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure EPSS 0.2%CVE-2025-54609MEDIUMOut-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2025-61860HIGHAn out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFEPSS 0.2%