Falhas do tipo CWE-125

5.182 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-31912MEDIUMOOBR in libpcap before 1.10.7EPSS 0.1%CVE-2026-77797LOWVelociraptor Prefetch parser out of boundsEPSS 0.1%CVE-2026-79616LOWOut-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt QuickEPSS 0.1%CVE-2025-29937MEDIUMAn out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory loEPSS 0.1%CVE-2026-18458MEDIUMOut-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.1%CVE-2026-102757HIGHAn unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode,EPSS 0.1%CVE-2025-27940MEDIUMOut-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Software side chEPSS 0.1%CVE-2026-11389MEDIUMOut-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.1%CVE-2026-18626MEDIUMOut-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.1%CVE-2018-9464HIGHIn multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalatioEPSS 0.1%CVE-2024-20093MEDIUMIn vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System eEPSS 0.1%CVE-2022-27832MEDIUMImproper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a craftedEPSS 0.1%CVE-2026-10305MEDIUMOut-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462EPSS 0.1%CVE-2025-36918HIGHIn aoc_service_read_message of aoc_ipc_core.c, there is a possible out of bounds read due to improper input validation. This could lead to lEPSS 0.1%CVE-2023-20840MEDIUMIn imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of prEPSS 0.1%CVE-2023-20848MEDIUMIn imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privileEPSS 0.1%CVE-2026-94284MEDIUMOut-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parserEPSS 0.1%CVE-2026-0135HIGHIn Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no additional EPSS 0.1%CVE-2023-42726MEDIUMIn TeleService, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with SystemEPSS 0.1%CVE-2024-20107MEDIUMIn da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additioEPSS 0.1%