Weaknesses of type CWE-125
5,180 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-12033MEDIUMOut of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process toEPSS 0.2%CVE-2024-6876MEDIUMOut-of-bounds read in OSCAT-LibraryEPSS 0.2%CVE-2026-2858MEDIUMwren-lang wren Source File wren_compiler.c peekChar out-of-boundsEPSS 0.2%CVE-2026-7949LOWOut of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leaEPSS 0.2%CVE-2025-23050LOWQLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero).EPSS 0.2%CVE-2025-22003MEDIUMcan: ucan: fix out of bound read in strscpy() sourceEPSS 0.2%CVE-2025-32776MEDIUMOpenRazer Vulnerable to Out of Bounds ReadEPSS 0.2%CVE-2024-9508HIGHHorner Automation Cscape Out-of-bounds ReadEPSS 0.2%CVE-2024-38389HIGHThere is an Out-of-bounds read vulnerability in TELLUS (v4.0.19.0 and earlier) and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a spEPSS 0.2%CVE-2022-20541MEDIUMIn phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local inforEPSS 0.2%CVE-2026-64201HIGHOut-of-Bounds Read Vulnerability in NI LabVIEW when loading VIEPSS 0.2%CVE-2026-64202HIGHOut-of-Bounds Read Vulnerability in NI LabVIEW when loading VIEPSS 0.2%CVE-2024-38658HIGHThere is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens EPSS 0.2%CVE-2026-57077HIGHYAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_lenEPSS 0.2%CVE-2025-47135MEDIUMDimension | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-3664MEDIUMxlnt-community xlnt Encrypted XLSX File compound_document.cpp read_directory out-of-boundsEPSS 0.2%CVE-2026-32864HIGHOut-of-Bounds Read in mgcore_SH_25_3!aligned_free()EPSS 0.2%CVE-2026-64203HIGHOut-of-Bounds Read Vulnerability in NI LabVIEW when loading VIEPSS 0.2%CVE-2026-32863HIGHOut-of-Bounds Read in sentry_transaction_context_set_operation()EPSS 0.2%CVE-2026-80490—Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringifiedEPSS 0.2%