Weaknesses of type CWE-125
5,176 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-69617HIGHWindows Resilient File System (ReFS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69630HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-78475MEDIUMGimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loaderEPSS 0.3%CVE-2026-13890MEDIUMOut of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process EPSS 0.3%CVE-2026-82330MEDIUMGimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds checkEPSS 0.3%CVE-2026-8541MEDIUMOut of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtaEPSS 0.3%CVE-2026-8543MEDIUMOut of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage inEPSS 0.3%CVE-2026-33450LOWOut of bounds read in Secure Access MacOS clients prior to 14.50EPSS 0.3%CVE-2026-82328MEDIUMGimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette countEPSS 0.3%CVE-2024-27529HIGHwasm3 139076a contains memory leaks in Read_utf8.EPSS 0.3%CVE-2026-13975MEDIUMOut of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2026-72952HIGHWindows Spaceport.sys Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-8546MEDIUMOut of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2024-45463HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.3%CVE-2026-31885MEDIUMFreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checksEPSS 0.3%CVE-2026-20611HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 andEPSS 0.3%CVE-2025-63523MEDIUMFeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticatEPSS 0.3%CVE-2024-50268HIGHusb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd()EPSS 0.3%CVE-2026-13480LOWOut-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handlerEPSS 0.3%CVE-2024-50278HIGHdm cache: fix potential out-of-bounds access on the first resumeEPSS 0.3%