Weaknesses of type CWE-125

5,180 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2026-61721HIGHFluidSynth: Heap-based buffer overrun for DLS samplesEPSS 0.2%CVE-2026-3663MEDIUMxlnt-community xlnt XLSX File compound_document.cpp xsgetn out-of-boundsEPSS 0.2%CVE-2024-37086MEDIUMVMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine withEPSS 0.2%CVE-2023-49144HIGHOut of bounds read in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.15-0, bhs-0.27 may allow a privileged user tEPSS 0.2%CVE-2026-21487MEDIUMiccDEV has Out-of-bounds Read, Use of Out-of-range Pointer Offset and Improper Input ValidationEPSS 0.2%CVE-2021-37687MEDIUMHeap OOB in TensorFlow Lite's `Gather*` implementationsEPSS 0.2%CVE-2026-27692HIGHiccDEV has HBO in CIccTagTextDescription::Release()EPSS 0.2%CVE-2026-3442MEDIUMBinutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linkerEPSS 0.2%CVE-2024-23808MEDIUMArkcompiler ets frontend has an out-of-bounds read vulnerabilityEPSS 0.2%CVE-2026-72522MEDIUMlibexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates dEPSS 0.2%CVE-2026-3441MEDIUMBinutils: gnu binutils: information disclosure via specially crafted xcoff object fileEPSS 0.2%CVE-2025-32412HIGHFuji Electric Smart Editor Out-of-bounds ReadEPSS 0.2%CVE-2026-28420MEDIUMVim has Heap-based Buffer Overflow and OOB Read in :terminalEPSS 0.2%CVE-2026-47104MEDIUMlibusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()EPSS 0.2%CVE-2026-2858MEDIUMwren-lang wren Source File wren_compiler.c peekChar out-of-boundsEPSS 0.2%CVE-2025-62525HIGHOpenWrt vulnerable to local privilage escalationEPSS 0.2%CVE-2021-29547LOWHeap out of bounds in `QuantizedBatchNormWithGlobalNormalization`EPSS 0.2%CVE-2025-32776MEDIUMOpenRazer Vulnerable to Out of Bounds ReadEPSS 0.2%CVE-2026-12033MEDIUMOut of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process toEPSS 0.2%CVE-2024-6876MEDIUMOut-of-bounds read in OSCAT-LibraryEPSS 0.2%