Weaknesses of type CWE-125

5,134 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2025-51602MEDIUMmmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMEPSS 0.4%CVE-2026-69345MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-27163MEDIUMAcrobat Reader | Out-of-bounds Read (CWE-125)EPSS 0.4%CVE-2026-69308MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-69367MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-68881MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-69303MEDIUMPush Message Routing Service Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-5873HIGHOut of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2024-51562MEDIUMbhyve(8) nvme_opc_get_log_page buffer over-readEPSS 0.4%CVE-2023-43692HIGHAn issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). Out-of-bound reads in striEPSS 0.4%CVE-2025-53859MEDIUMNGINX ngx_mail_smtp_module vulnerabilityEPSS 0.4%CVE-2025-55086MEDIUMIn NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked indEPSS 0.4%CVE-2026-44041MEDIUMUltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminatedEPSS 0.4%CVE-2025-47112MEDIUMAcrobat Reader | Out-of-bounds Read (CWE-125)EPSS 0.4%CVE-2026-9928HIGHOut of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crEPSS 0.4%CVE-2026-82072HIGHOut of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via EPSS 0.4%CVE-2026-15903HIGHOut of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.4%CVE-2026-78978HIGHOut of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitraryEPSS 0.4%CVE-2026-87440HIGHOut of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox vEPSS 0.4%CVE-2024-29948LOWThere is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending sEPSS 0.4%