Weaknesses of type CWE-125

5,161 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2025-24182MEDIUMAn out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.EPSS 0.3%CVE-2024-20712MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability IIIEPSS 0.3%CVE-2022-26369MEDIUMOut-of-bounds read in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentialEPSS 0.3%CVE-2024-20714MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VEPSS 0.3%CVE-2024-20710MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability IEPSS 0.3%CVE-2024-20771MEDIUMBridge 2024 MOV File parsing memory corruptionEPSS 0.3%CVE-2025-4098HIGHOut-of-bounds Read in Horner Automation CscapeEPSS 0.3%CVE-2024-49529MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-20715MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VIIIEPSS 0.3%CVE-2024-20796MEDIUMAdobe Animation SWF File Parsing Memory CorruptionEPSS 0.3%CVE-2022-46440MEDIUMttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.EPSS 0.3%CVE-2026-10999MEDIUMInteger overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer procEPSS 0.3%CVE-2026-18716HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2022-34677MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause EPSS 0.3%CVE-2024-20138HIGHIn wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure witEPSS 0.3%CVE-2023-34401LOWMercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which EPSS 0.3%CVE-2026-10927HIGHOut of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potEPSS 0.3%CVE-2026-48040MEDIUMnetty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory AccessEPSS 0.3%CVE-2026-10889HIGHOut of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to poEPSS 0.3%CVE-2021-22484HIGHSome Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful exploitation of this vulnEPSS 0.3%