Weaknesses of type CWE-125

5,159 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2026-69532HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-32391—The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.5, iOS 16.5 and iPadOS 16.5, maEPSS 0.3%CVE-2026-26153HIGHWindows Encrypted File System (EFS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50422HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69265HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-56176HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69324HIGHWindows Performance Monitor Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69561HIGHWindows CD-ROM Driver Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62876HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-70569HIGHWindows Spaceport.sys Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-62880HIGHWindows NTFS Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-65786HIGHDesktop Window Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-42387LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.3%CVE-2025-22392MEDIUMOut-of-bounds read in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable iEPSS 0.3%CVE-2022-42386LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.3%CVE-2023-26339MEDIUMZDI-CAN-19388: Adobe Dimension OBJ File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-26345MEDIUMZDI-CAN-19494: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-26338MEDIUMZDI-CAN-19410: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-26351MEDIUMZDI-CAN-19507: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-26354MEDIUMZDI-CAN-19519: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%