Falhas do tipo CWE-125

5.180 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-19028MEDIUMHDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds readEPSS 0.2%CVE-2025-20688MEDIUMIn wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure EPSS 0.2%CVE-2026-54633MEDIUMPoDoFo: Heap Out-of-Bounds Read in Indexed Color Space Image Decoding (FetchScanLine)EPSS 0.2%CVE-2026-65979MEDIUMOpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN)EPSS 0.2%CVE-2026-53566MEDIUMOut-of-bounds memory readEPSS 0.2%CVE-2025-55307LOWAn issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a craftedEPSS 0.2%CVE-2025-64893HIGHDNG SDK | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-90557MEDIUMFreeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via SavegameEPSS 0.2%CVE-2025-5046HIGHDGN File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2026-2241MEDIUMjanet-lang janet os.c os_strftime out-of-boundsEPSS 0.2%CVE-2026-0155MEDIUMIn ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information discEPSS 0.2%CVE-2024-32667LOWOut-of-bounds read for some OpenCL(TM) software may allow an authenticated user to potentially enable denial of service via local access.EPSS 0.2%CVE-2025-6034HIGHOut of Bounds Read in DefaultFontOptions() in NI Circuit Design SuiteEPSS 0.2%CVE-2025-10101HIGHAvast antivirus heap buffer OOB read when scanning a malformed Mach-O fileEPSS 0.2%CVE-2026-28419MEDIUMVim has Heap-based Buffer Underflow in Emacs tags parsingEPSS 0.2%CVE-2025-14421LOWpdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2023-30760LOWOut-of-bounds read in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticatedEPSS 0.2%CVE-2023-25494MEDIUM A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attackeEPSS 0.2%CVE-2023-21430MEDIUMAn out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 ReleaseEPSS 0.2%CVE-2024-32893HIGHIn _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local informatEPSS 0.2%