Falhas do tipo CWE-125

5.180 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-4367MEDIUMLibxpm: libxpm: denial of service via out-of-bounds read in xpm file parsingEPSS 0.2%CVE-2022-41585HIGHThe kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.EPSS 0.2%CVE-2026-13326MEDIUMOut-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC moduleEPSS 0.2%CVE-2025-23272MEDIUMNVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially crafted JPEG file. EPSS 0.2%CVE-2026-5713MEDIUMOut-of-bounds read/write during remote profiling and asyncio process introspection when connecting to malicious targetEPSS 0.2%CVE-2026-102714HIGH`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whosEPSS 0.2%CVE-2026-65349MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8,EPSS 0.2%CVE-2026-57253MEDIUMFoxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2026-88054MEDIUMTesseract: Denial of service via empty-stack dereference in Plumbing/Series at model loadEPSS 0.2%CVE-2026-102726MEDIUMUnbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds ReadEPSS 0.2%CVE-2026-57241MEDIUMFoxit PDF Editor/Reader Page Out-of-bounds Read VulnerabilityEPSS 0.2%CVE-2021-41210HIGHHeap OOB read in `tf.raw_ops.SparseCountSparseOutput`EPSS 0.2%CVE-2026-57243MEDIUMFoxit PDF Editor/Reader Page Out-of-bounds Read VulnerabilityEPSS 0.2%CVE-2026-45258HIGHMultiple vulnerabilities in the sound(4) mmap pathEPSS 0.2%CVE-2026-102725MEDIUMOut-of-bounds Read from Unvalidated MSRP Attribute List LengthEPSS 0.2%CVE-2026-102720MEDIUMA DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received EPSS 0.2%CVE-2025-39901HIGHi40e: remove read access to debugfs filesEPSS 0.2%CVE-2026-33451HIGHArbitrary read/write vulnerability in Windows clients prior to 14.50EPSS 0.2%CVE-2026-42494MEDIUMbuffer overruns in libfsimage iso9660 handlingEPSS 0.2%CVE-2026-57257MEDIUMSecurity vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB ReadEPSS 0.2%