Weaknesses of type CWE-125

5,179 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2026-36613MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POSEPSS 0.2%CVE-2018-9349MEDIUMIn mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This could lead to denial of service with no aEPSS 0.2%CVE-2026-34776MEDIUMElectron: Out-of-bounds read in second-instance IPC on macOS and LinuxEPSS 0.2%CVE-2023-25008HIGHA malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result iEPSS 0.2%CVE-2025-1399LOWOut-of-bounds Read in libplctag libraryEPSS 0.2%CVE-2023-0621HIGHCVE-2023-0621EPSS 0.2%CVE-2025-1400LOWOut-of-bounds Read in libplctag libraryEPSS 0.2%CVE-2024-52613MEDIUMA heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) via a crafteEPSS 0.2%CVE-2026-101204MEDIUMFastStone Image Viewer TGA Image FSViewer.exe out-of-boundsEPSS 0.2%CVE-2025-1652HIGHMODEL File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2025-1433HIGHMODEL File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2026-101205MEDIUMFastStone Image Viewer PCX Decoder out-of-boundsEPSS 0.2%CVE-2025-1431HIGHSLDPRT File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2025-24448MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-85052LOWOut of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2025-21789HIGHLoongArch: csum: Fix OoB access in IP checksum code for negative lengthsEPSS 0.2%CVE-2022-41613HIGHBentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when parsing DGN files, wEPSS 0.2%CVE-2026-79004LOWOut of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to reEPSS 0.2%CVE-2026-0956HIGHOut-Of-Bounds Read in Digilent DASYLabEPSS 0.2%CVE-2025-21920HIGHvlan: enforce underlying device typeEPSS 0.2%