Weaknesses of type CWE-125
5,179 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2025-9327LOWFoxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-9325LOWFoxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-9323LOWFoxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-43346MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOEPSS 0.2%CVE-2026-5392LOWwolfSSL heap OOB read in PKCS7 SignedData streamingEPSS 0.2%CVE-2024-26588HIGHLoongArch: BPF: Prevent out-of-bounds memory accessEPSS 0.2%CVE-2023-39187HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-39182HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2026-12026MEDIUMOut of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2026-20421MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connecEPSS 0.2%CVE-2026-28526LOWBlueKitchen BTstack < 1.8.1 AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_* Handlers OOB ReadEPSS 0.2%CVE-2023-39183HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-39186HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-27912HIGHA maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious actor can leverage thEPSS 0.2%CVE-2023-39184HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-39185HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2026-25920MEDIUMSumatraPDF has a heap out-of-bounds read in MOBI HuffDic decompressorEPSS 0.2%CVE-2023-3487HIGHInteger overflow in Silicon Labs Gecko Bootloader leads to unbounded memory accessEPSS 0.2%CVE-2023-32403—This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.EPSS 0.2%CVE-2024-33493HIGHA vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read EPSS 0.2%