Falhas do tipo CWE-125

5.181 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-9032HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed PE fileEPSS 0.1%CVE-2026-56136MEDIUMIn NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly EPSS 0.1%CVE-2025-9033HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 3)EPSS 0.1%CVE-2026-19086LOWIBM i is Affected By Multiple Vulnerabilities in PASE [, ]EPSS 0.1%CVE-2022-25665MEDIUMInformation disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon MobileEPSS 0.1%CVE-2026-75147MEDIUMFFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.cEPSS 0.1%CVE-2026-10267MEDIUMjanet-lang janet debug.c doframe out-of-boundsEPSS 0.1%CVE-2025-41278HIGHNozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackEPSS 0.1%CVE-2026-49314HIGHOOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availabiliEPSS 0.1%CVE-2022-39130MEDIUMIn face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in EPSS 0.1%CVE-2026-20751HIGHOut-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers EPSS 0.1%CVE-2026-20518MEDIUMIn geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if aEPSS 0.1%CVE-2022-42774MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2024-27223MEDIUMIn EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check.EPSS 0.1%CVE-2026-0106CRITICALIn vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%CVE-2022-42773MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-102567MEDIUMCTranslate2 before 4.8.1 Out-of-Bounds Read via Model DeserializationEPSS 0.1%CVE-2022-42761MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2023-43694MEDIUMAn issue was discovered in Malwarebytes 4.6.14.326 and before and 5.1.5.116 and before (and Nebula 2020-10-21 and later). An Out of bounds rEPSS 0.1%CVE-2026-88835MEDIUMBusybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packagesEPSS 0.1%