Falhas do tipo CWE-125

5.180 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-18090MEDIUMGdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle blockEPSS 0.2%CVE-2021-37655HIGHHeap OOB in `ResourceScatterUpdate` in TensorFlowEPSS 0.2%CVE-2022-50394HIGHi2c: ismt: Fix an out-of-bounds bug in ismt_access()EPSS 0.2%CVE-2025-20687MEDIUMIn Bluetooth driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local denial of service witEPSS 0.2%CVE-2021-37641HIGHHeap OOB in `RaggedGather` in TensorFlowEPSS 0.2%CVE-2021-37664HIGHHeap OOB in boosted trees in TensorFlowEPSS 0.2%CVE-2026-21345HIGHSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-63272MEDIUMHeap buffer overflow in WMF text record importEPSS 0.2%CVE-2026-17124HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2026-2242MEDIUMjanet-lang janet specials.c janetc_if out-of-boundsEPSS 0.2%CVE-2023-32471MEDIUMDell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with highEPSS 0.2%CVE-2026-45329HIGHESF-IDF: Out-of-Bounds Read in ESP-TEE Secure Service WrappersEPSS 0.2%CVE-2026-2240MEDIUMjanet-lang janet compile.c janetc_pop_funcdef out-of-boundsEPSS 0.2%CVE-2021-37654HIGHHeap OOB and CHECK fail in `ResourceGather` in TensorFlowEPSS 0.2%CVE-2023-7066HIGHSiemens Teamcenter Visualization and JT2Go Out-of-bounds ReadEPSS 0.2%CVE-2026-63274MEDIUMHeap buffer overflow in PDF import stream handlingEPSS 0.2%CVE-2022-42515MEDIUMIn MiscService::DoOemSetRtpPktlossThreshold of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This cEPSS 0.2%CVE-2021-37635HIGHHeap out of bounds access in sparse reduction operations in TensorFlowEPSS 0.2%CVE-2026-43747HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TEPSS 0.2%CVE-2026-24196HIGHNVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerEPSS 0.2%