Falhas do tipo CWE-125

5.181 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2025-15038MEDIUMAn Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an uEPSS 0.1%CVE-2026-0799HIGHOOBR and OOBW in libpcap before 1.10.7EPSS 0.1%CVE-2022-25819MEDIUMOOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.EPSS 0.1%CVE-2026-91810MEDIUMFoxit PDF Editor/Reader Doc Object Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-91817MEDIUMFoxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.1%CVE-2026-18857LOWThis Power System update is being released to addressEPSS 0.1%CVE-2026-91807MEDIUMFoxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-13478MEDIUMOut-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_blocks_countEPSS 0.1%CVE-2026-91808MEDIUMFoxit PDF Editor/Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.1%CVE-2025-21438HIGHOut-of-bounds Read in Windows WLAN HostEPSS 0.1%CVE-2023-21206—In initiateVenueUrlAnqpQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could leadEPSS 0.1%CVE-2023-32878MEDIUMIn battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with SEPSS 0.1%CVE-2024-20058MEDIUMIn keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with SyEPSS 0.1%CVE-2026-10998MEDIUMOut of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of boEPSS 0.1%CVE-2026-79616LOWOut-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt QuickEPSS 0.1%CVE-2026-61862LOWImageMagick before 7.1.2-26 Information Disclosure via identifyEPSS 0.1%CVE-2023-20719MEDIUMIn pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with SEPSS 0.1%CVE-2018-9383MEDIUMIn asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local informEPSS 0.1%CVE-2025-27708MEDIUMOut-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel mayEPSS 0.1%CVE-2026-77797LOWVelociraptor Prefetch parser out of boundsEPSS 0.1%