Weaknesses of type CWE-125
5,180 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2025-46316MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS TahoeEPSS 0.3%CVE-2026-10979MEDIUMOut of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information frEPSS 0.3%CVE-2026-10985MEDIUMOut of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML paEPSS 0.3%CVE-2020-1824LOWThere are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some EPSS 0.3%CVE-2026-35217MEDIUMNanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds ReadEPSS 0.3%CVE-2025-43265MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS SequEPSS 0.3%CVE-2026-24189HIGHNVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliEPSS 0.3%CVE-2026-44067LOWEA header parsing heap over-readEPSS 0.3%CVE-2023-48638MEDIUMAdobe Substance 3D Designer 13.0.2 build 6942 Vulnerability IIIEPSS 0.3%CVE-2026-41034MEDIUMONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and othEPSS 0.3%CVE-2023-48636MEDIUMAdobe Substance 3D Designer 13.0.2 build 6942 Vulnerability IVEPSS 0.3%CVE-2023-47081MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability IIEPSS 0.3%CVE-2026-102555HIGHLibsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decodingEPSS 0.3%CVE-2026-15114HIGHOut of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corrupEPSS 0.3%CVE-2026-9121HIGHOut of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.3%CVE-2023-51559LOWFoxit PDF Reader Doc Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-47080MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VIEPSS 0.3%CVE-2026-79239MEDIUMOut of bounds read in Tint in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory insideEPSS 0.3%CVE-2022-47520HIGHAn issue was discovered in the Linux kernel before 6.0.11. Missing offset validation in drivers/net/wireless/microchip/wilc1000/hif.c in theEPSS 0.3%CVE-2025-57697MEDIUMAstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image_bs64 function definEPSS 0.3%