Weaknesses of type CWE-125
5,179 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-7904MEDIUMOut of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a EPSS 0.2%CVE-2025-30302MEDIUMAdobe Framemaker | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-11160MEDIUMOut of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive inforEPSS 0.2%CVE-2025-30303MEDIUMAdobe Framemaker | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-7983MEDIUMOut of bounds read in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML paEPSS 0.2%CVE-2026-11051MEDIUMOut of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive inforEPSS 0.2%CVE-2026-11075MEDIUMOut of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from EPSS 0.2%CVE-2024-20787MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-50128HIGHnet: wwan: fix global oob in wwan_rtnl_policyEPSS 0.2%CVE-2024-47456MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-41863MEDIUMAdobe Substance 3D Sampler Memory Corruption Out-of-Bounds-READ Vulnerability III, when parsing DNG fileEPSS 0.2%CVE-2022-39141—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.2%CVE-2024-47437MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-41645HIGHOut-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and/or execute arbitrarEPSS 0.2%CVE-2024-30287MEDIUMAdobe FrameMaker PDF File Pparsing Out of Bound ReadEPSS 0.2%CVE-2024-30286MEDIUMAdobe FrameMaker DOC File Parsing Memory CorruptionEPSS 0.2%CVE-2024-47454MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2024-47449MEDIUMAudition | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-39137—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34EPSS 0.2%CVE-2024-47440MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%