Weaknesses of type CWE-125
5,136 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-56378MEDIUMImageMagick - Heap Out-of-Bounds Read in PCD DecoderEPSS 0.4%CVE-2026-87824HIGHzstd-jni 1.3.3-1 through 1.5.7-13 Out-of-Bounds Read via Zstd.trainFromBufferDirectEPSS 0.4%CVE-2026-28979MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7EPSS 0.4%CVE-2026-43703MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS SonoEPSS 0.4%CVE-2026-41069MEDIUMlibheif allows Out-of-bounds vector access leading to invalid dereference (DoS)EPSS 0.4%CVE-2026-34971CRITICALWasmtime miscompiled guest heap access enables sandbox escape on aarch64 CraneliftEPSS 0.4%CVE-2026-12478MEDIUMLibsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)EPSS 0.4%CVE-2026-82066MEDIUMHeap Out-of-Bounds Read in MongoDB Server Query Planning ComponentEPSS 0.4%CVE-2026-14740CRITICALDBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL commentEPSS 0.4%CVE-2026-35201MEDIUMDiscount has an Out-of-bounds Read in rdiscountEPSS 0.4%CVE-2023-0972CRITICALBuffer overflow in S0 Decryption on Z/IP GatweayEPSS 0.4%CVE-2026-0708HIGHLibucl: libucl: denial of service via embedded null byte in ucl inputEPSS 0.4%CVE-2023-25658HIGHTensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGradEPSS 0.4%CVE-2026-12891MEDIUMGstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parserEPSS 0.4%CVE-2023-37353LOWKofax Power PDF JPG File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-37356LOWKofax Power PDF GIF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-65365MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.4%CVE-2025-0518MEDIUMUnchecked sscanf return value which leads to memory data leakEPSS 0.4%CVE-2022-42399HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2023-37351LOWKofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%