Falhas do tipo CWE-125

5.126 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2026-62814MEDIUMWindows DHCP Server Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-21530MEDIUMVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that aEPSS 0.5%CVE-2024-44910HIGHNASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).EPSS 0.5%CVE-2022-20792HIGHA vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 aEPSS 0.5%CVE-2026-6785HIGHMemory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150EPSS 0.5%CVE-2025-24050HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-24059HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-6786HIGHMemory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150EPSS 0.5%CVE-2025-24048HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-70634HIGHTimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse IteratorEPSS 0.5%CVE-2025-62603LOWFastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabledEPSS 0.5%CVE-2022-46349HIGHA vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.5%CVE-2026-44978MEDIUMxrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verificationEPSS 0.5%CVE-2026-28815HIGHA remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentiallyEPSS 0.5%CVE-2024-35385MEDIUMAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in the mjs.c file.EPSS 0.5%CVE-2020-17390LOWThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker muEPSS 0.5%CVE-2025-32707HIGHNTFS Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2021-44448—A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected prEPSS 0.5%CVE-2021-44436—A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected prEPSS 0.5%CVE-2023-50926HIGHUnvalidated DIO prefix info length in RPL-Lite in Contiki-NGEPSS 0.5%