Falhas do tipo CWE-125

5.180 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-40740HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of boundEPSS 0.2%CVE-2022-41601LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2025-40739HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of boundEPSS 0.2%CVE-2026-15003MEDIUMBinutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of serviceEPSS 0.2%CVE-2024-39612MEDIUMBackground Task Manager has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%CVE-2022-41600LOWThe phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).SuccessfEPSS 0.2%CVE-2024-12082MEDIUMAbility Runtime has an out-of-bounds read permission bypass vulnerabilityEPSS 0.2%CVE-2024-9978MEDIUMLiteos_a has an out-of-bounds read vulnerabilityEPSS 0.2%CVE-2026-58307MEDIUMOut-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. ThiEPSS 0.2%CVE-2026-58304MEDIUMOut-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:EPSS 0.2%CVE-2026-57896MEDIUMAutomationDirect Productivity Suite Out-of-bounds ReadEPSS 0.2%CVE-2026-49509MEDIUMOut-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d94EPSS 0.1%CVE-2022-41577HIGHThe kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this EPSS 0.1%CVE-2025-39840HIGHaudit: fix out-of-bounds read in audit_compare_dname_path()EPSS 0.1%CVE-2026-43767MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AEPSS 0.1%CVE-2026-90463MEDIUMSssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)EPSS 0.1%CVE-2026-20496MEDIUMIn geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malEPSS 0.1%CVE-2023-28074MEDIUMDell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains aEPSS 0.1%CVE-2024-8159MEDIUMDeep Freeze 9.00.020.5760 - Out-of-bounds readEPSS 0.1%CVE-2026-30935MEDIUMImageMagick has a heap Buffer Over-Read in BilateralBlurImageEPSS 0.1%