Falhas do tipo CWE-125

5.180 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-57257MEDIUMSecurity vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB ReadEPSS 0.2%CVE-2026-88054MEDIUMTesseract: Denial of service via empty-stack dereference in Plumbing/Series at model loadEPSS 0.2%CVE-2025-40764HIGHA vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All versions < V2412.0002).EPSS 0.2%CVE-2024-39806MEDIUMLiteos_a has an out-of-bounds Read vulnerabilityEPSS 0.2%CVE-2024-45070MEDIUMLiteos_a has an out-of-bounds read vulnerabilityEPSS 0.2%CVE-2026-22185MEDIUMOpenLDAP LMDB mdb_load Heap Buffer Underflow in readline()EPSS 0.2%CVE-2026-21488MEDIUMiccDEV has Out-of-bounds Read, Heap-based Buffer Overflow and Improper Null TerminationEPSS 0.2%CVE-2025-20042MEDIUMLiteos-A has an out of bounds read vulnerabilityEPSS 0.2%CVE-2025-12829MEDIUMAn uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data and serialize it to IoEPSS 0.2%CVE-2026-2810MEDIUMEndpoint DLP Driver Out-of-Bounds ReadEPSS 0.2%CVE-2024-12082MEDIUMAbility Runtime has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%CVE-2026-60140MEDIUMAutomationDirect Productivity Suite Out-of-bounds ReadEPSS 0.2%CVE-2022-41595LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41593LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2022-41598LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2026-81884LOWradare2: Heap out-of-bounds read in radare2 Mach-O LC_DATA_IN_CODE parserEPSS 0.2%CVE-2022-41601LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2026-58304MEDIUMOut-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:EPSS 0.2%CVE-2024-9978MEDIUMLiteos_a has an out-of-bounds read vulnerabilityEPSS 0.2%CVE-2024-47402LOWLiteos_a has an Out-of-bounds Read vulnerabilityEPSS 0.2%