Weaknesses of type CWE-125

5,180 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2025-43377MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2EPSS 0.2%CVE-2026-13705HIGHImager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rleEPSS 0.2%CVE-2026-12897HIGHOut-of-bounds read in Horner Automation CscapeEPSS 0.2%CVE-2026-52295LOWFFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavfEPSS 0.2%CVE-2025-52938MEDIUMPotential heap-based buffer over-read vulnerability in NotepadNextEPSS 0.2%CVE-2026-77237HIGHMissing type validation in xQueueAddToSet in FreeRTOS-KernelEPSS 0.2%CVE-2026-59146HIGHData::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slotEPSS 0.2%CVE-2026-22717LOWVMware Workstation out-of-bound read vulnerabilityEPSS 0.2%CVE-2026-45612MEDIUMrz-libdemangle: Out of bound read in rust demanglerEPSS 0.2%CVE-2021-37651HIGHHeap buffer overflow in `FractionalAvgPoolGrad` in TensorFlowEPSS 0.2%CVE-2026-34556MEDIUMiccDEV: HBO in icAnsiToUtf8()EPSS 0.2%CVE-2026-71498MEDIUMnode-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScriptEPSS 0.2%CVE-2022-20574MEDIUMIn sec_sysmmu_info of drm_fw.c, there is a possible out of bounds read due to improper input validation. This could lead to local informatioEPSS 0.2%CVE-2022-40708LOWAn Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local EPSS 0.2%CVE-2026-34554MEDIUMiccDEV: HBO in CIccApplyCmmSearch::costFunc()EPSS 0.2%CVE-2022-20575MEDIUMIn read_ppmpu_info of drm_fw.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local informatioEPSS 0.2%CVE-2022-42517MEDIUMIn MiscService::DoOemSetTcsFci of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to EPSS 0.2%CVE-2024-33653HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past EPSS 0.2%CVE-2025-14055LOWInteger underflow in Secure NCP hostEPSS 0.2%CVE-2024-33654HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past EPSS 0.2%