Falhas do tipo CWE-125

5.126 resultados

Leitura fora dos limites de memória

Ocorre quando o código tenta ler dados de uma posição de memória fora do intervalo alocado para um buffer ou array. O programa não valida o índice ou tamanho antes de acessar, causando leitura de dados inválidos, corrupção de informações ou revelação de dados sensíveis da memória adjacente.

Exemplo

Um processador de imagem PNG lê 4 bytes de um buffer de 2 bytes para validar uma assinatura, ou uma função copia uma string sem verificar se o índice fornecido pelo usuário extrapola o tamanho real do array. Em ambos os casos, dados fora do escopo pretendido são lidos.

Como mitigar

Sempre validar índices e comprimentos contra os limites reais do buffer antes de qualquer leitura. Usar funções seguras (ex: `strncpy` em vez de `strcpy`, bounds-checking em loops) e implementar testes com entradas extremas (size zero, índices negativos, valores muito grandes).

CVE-2021-44431—A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected prEPSS 0.5%CVE-2025-53379HIGHA out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remotEPSS 0.5%CVE-2026-69244HIGHAIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)EPSS 0.5%CVE-2023-52727HIGHOpen Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.EPSS 0.5%CVE-2020-8872MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.1-47117. An EPSS 0.5%CVE-2025-67721MEDIUMAircompressor's Snappy and LZ4 Java-based decompressor implementation can leak information from reused output bufferEPSS 0.5%CVE-2023-6606HIGHKernel: out-of-bounds read vulnerability in smbcalcsizeEPSS 0.5%CVE-2026-55122HIGHMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-51606HIGHKofax Power PDF U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-32188HIGHMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-34000MEDIUMXwayland: xorg: x.org x server: information disclosure and denial of service via out-of-bounds read in xkb geometry processing.EPSS 0.5%CVE-2025-27931MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EPSS 0.5%CVE-2024-34244HIGHlibmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed EPSS 0.5%CVE-2026-62959HIGHCoturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)EPSS 0.5%CVE-2025-62202HIGHMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-63383HIGHLibevent: decode_tag_internal() can lead to out-of-bounds readEPSS 0.5%CVE-2025-62468MEDIUMWindows Defender Firewall Service Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-58528MEDIUMWindows USB Audio Class Driver Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-78455MEDIUMXbox Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-86227LOWvalkey-io valkey kvstore.c kvstoreGetHashtable out-of-boundsEPSS 0.5%