Weaknesses of type CWE-125

5,159 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2022-43282HIGHwasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.EPSS 0.3%CVE-2022-43280HIGHwasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.EPSS 0.3%CVE-2024-35423HIGHvmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.EPSS 0.3%CVE-2026-5292HIGHOut of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read vEPSS 0.3%CVE-2025-7698MEDIUMOut-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic PlEPSS 0.3%CVE-2024-20127HIGHIn Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no addiEPSS 0.3%CVE-2024-20129HIGHIn Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no addiEPSS 0.3%CVE-2025-0437MEDIUMOut of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.3%CVE-2024-20128HIGHIn Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no addiEPSS 0.3%CVE-2026-12298MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2026-44518MEDIUMliboqs: XMSS Buffer Overread BugEPSS 0.3%CVE-2026-24812CRITICALAn improper pointer arithmetic in root-project/root at builtins/zlib/inftrees.cEPSS 0.3%CVE-2026-66759HIGHGimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns imagesEPSS 0.3%CVE-2023-4721MEDIUMOut-of-bounds Read in gpac/gpacEPSS 0.3%CVE-2024-22957MEDIUMswftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the function dict_do_lookup in swftools/lib/q.c:1190.EPSS 0.3%CVE-2022-42901HIGHBentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when opening crafted XMTEPSS 0.3%CVE-2026-46344MEDIUMliboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter mismatch (xmss_commons.c:194)EPSS 0.3%CVE-2025-53051LOWVulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. EasilyEPSS 0.3%CVE-2026-56362LOWImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata DesynchronizationEPSS 0.3%CVE-2026-9889HIGHOut of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a EPSS 0.3%