Weaknesses of type CWE-125
5,179 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2025-30420HIGHOut of Bounds Read in Bitmap::InternalDraw() in NI Circuit Design SuiteEPSS 0.2%CVE-2023-39986HIGHOut-of-bounds Read Vulnerability in Hitachi EH-VIEW (Designer)EPSS 0.2%CVE-2026-91958MEDIUMFreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor IndexEPSS 0.2%CVE-2025-9136MEDIUMlibretro RetroArch file_stream.c filestream_vscanf out-of-boundsEPSS 0.2%CVE-2022-40136MEDIUMAn information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker wiEPSS 0.2%CVE-2026-57432HIGHPerl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpackEPSS 0.2%CVE-2025-54201MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54197MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-40135MEDIUMAn information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and EPSS 0.2%CVE-2025-54186MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54204MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-40134MEDIUMAn information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access andEPSS 0.2%CVE-2025-54200MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54188MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54205MEDIUMSubstance3D - Sampler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54194MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54189MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54199MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-43361HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7.2, macOS EPSS 0.2%CVE-2025-54191MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%