Weaknesses of type CWE-125

5,126 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2022-2581HIGHOut-of-bounds Read in vim/vimEPSS 0.5%CVE-2026-56099MEDIUMOpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS InputEPSS 0.5%CVE-2026-34876HIGHAn issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows atEPSS 0.5%CVE-2025-59208HIGHWindows MapUrlToZone Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-64899HIGHAcrobat Reader | Out-of-bounds Read (CWE-125)EPSS 0.5%CVE-2026-43630MEDIUMllama.cpp b5702–b7653 Out-of-Bounds Read Information DisclosureEPSS 0.5%CVE-2025-29365CRITICALspimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.EPSS 0.5%CVE-2025-60709HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-7668MEDIUMMikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-boundsEPSS 0.5%CVE-2026-25884LOWExiv2: Out-of-bounds read in CrwMap::decode0x0805EPSS 0.5%CVE-2023-32017HIGHMicrosoft PostScript Printer Driver Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-48688HIGHFastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The functiEPSS 0.5%CVE-2023-24862MEDIUMWindows Secure Channel Denial of Service VulnerabilityEPSS 0.5%CVE-2026-59198MEDIUMPillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated imagesEPSS 0.5%CVE-2026-56193HIGHMicrosoft Office Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-4693MEDIUMGrub2: out-of-bounds read at fs/ntfs.cEPSS 0.5%CVE-2023-39396—Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.EPSS 0.5%CVE-2024-44279MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS VeEPSS 0.5%CVE-2026-48092MEDIUM7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)EPSS 0.5%CVE-2025-32705HIGHMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 0.5%