Weaknesses of type CWE-125
5,179 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-21322HIGHAfter Effects | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-21324HIGHAfter Effects | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-39188HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-27401HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of EPSS 0.2%CVE-2023-27402HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of EPSS 0.2%CVE-2026-56374MEDIUMImageMagick - Heap Buffer Overflow in FTXT Encoder via format ParameterEPSS 0.2%CVE-2023-27405HIGHA vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of EPSS 0.2%CVE-2024-26702MEDIUMiio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRCEPSS 0.2%CVE-2025-21742HIGHusbnet: ipheth: use static NDP16 location in URBEPSS 0.2%CVE-2025-47754HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!Conv_Macro_Data function. Opening specially crafted V7 oEPSS 0.2%CVE-2024-50227HIGHthunderbolt: Fix KASAN reported stack out-of-bounds read in tb_retimer_scan()EPSS 0.2%CVE-2026-12303MEDIUMInformation disclosure due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.2%CVE-2025-47756HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CGamenDataRom::set_mr400_strc function. Opening speciallEPSS 0.2%CVE-2025-47753HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CDrawSLine::GetRectArea function. Opening specially crafEPSS 0.2%CVE-2025-21741HIGHusbnet: ipheth: fix DPE OoB readEPSS 0.2%CVE-2026-21278MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-47757HIGHV-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6MemInIF.dll!set_plc_type_default function. Opening specially crafEPSS 0.2%CVE-2025-32100MEDIUMAn issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380,EPSS 0.2%CVE-2026-2869MEDIUMjanet-lang janet handleattr specials.c janetc_varset out-of-boundsEPSS 0.2%CVE-2026-8084MEDIUMOSGeo gdal HDF-EOS Grid File SWapi.c memmove out-of-boundsEPSS 0.2%