Weaknesses of type CWE-125

5,179 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2025-7252HIGHIrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-61799HIGHDimension | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-7267HIGHIrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-43551MEDIUMSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-34961MEDIUMbarebox ext4 Extent Parsing Out-of-Bounds ReadEPSS 0.2%CVE-2018-9429MEDIUMIn buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to informatioEPSS 0.2%CVE-2024-50259MEDIUMnetdevsim: Add trailing zero to terminate the string in nsim_nexthop_bucket_activity_write()EPSS 0.2%CVE-2025-1659HIGHDWFX File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2025-1658HIGHDWFX File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2026-84270MEDIUMGvfs: mtp: out-of-bounds read in do_read()EPSS 0.2%CVE-2025-49525MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54262HIGHSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-30795HIGHA vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4), Parasolid V34.0 (All versions < EPSS 0.2%CVE-2023-29939MEDIUMllvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv:EPSS 0.2%CVE-2025-30313MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2023-24558HIGHA vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The EPSS 0.2%CVE-2021-29551LOWOOB read in `MatrixTriangularSolve`EPSS 0.2%CVE-2026-43753MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, maEPSS 0.2%CVE-2023-33123HIGHA vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), TeamcenEPSS 0.2%CVE-2023-30796HIGHA vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4). The affected applications contaiEPSS 0.2%