Weaknesses of type CWE-125
5,180 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2025-9447HIGHOut-Of-Bounds Read affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2025-14408LOWSoda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2026-75904MEDIUMlibmodplug <= 0.8.9.1 - Out-of-Bounds Read in pat_smplooped via Crafted MIDI FileEPSS 0.2%CVE-2026-57452MEDIUMVim: Out-of-bounds Read with libsodium-encrypted FilesEPSS 0.2%CVE-2026-35176HIGHopenFPGALoader has a heap buffer overflow in POFParser::parseSection() via crafted .pof fileEPSS 0.2%CVE-2026-88048HIGHTesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatchEPSS 0.2%CVE-2024-11268MEDIUMPDF File Parsing Vulnerability in Autodesk RevitEPSS 0.2%CVE-2026-35170HIGHopenFPGALoader has a heap buffer overflow in BitParser::parseHeader() via crafted .bit fileEPSS 0.2%CVE-2022-42510MEDIUMIn StringsRequestData::encode of requestdata.cpp, there is a possible out of bounds read due to improper input validation. This could lead tEPSS 0.2%CVE-2026-50643MEDIUMOut‑of‑Bounds Read in 8ccEPSS 0.2%CVE-2022-42514MEDIUMIn ProtocolImsBuilder::BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing bounds check. This EPSS 0.2%CVE-2026-5071MEDIUMcan: Local Denial of Service via SocketCAN SendEPSS 0.2%CVE-2026-11183MEDIUMOut of bounds read in GWP-ASan in Google Chrome prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information EPSS 0.2%CVE-2021-37670MEDIUMHeap OOB in `UpperBound` and `LowerBound` in TensorFlowEPSS 0.2%CVE-2026-0157MEDIUMIn RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosurEPSS 0.2%CVE-2026-57454MEDIUMVim: Out-of-bounds Read with Text PropertiesEPSS 0.2%CVE-2024-20071MEDIUMIn wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure witEPSS 0.2%CVE-2026-31794MEDIUMiccDEV has a SEGV in CIccCLUT::Interp3d()EPSS 0.2%CVE-2022-42516MEDIUMIn ProtocolSimBuilderLegacy::BuildSimGetGbaAuth of protocolsimbuilderlegacy.cpp, there is a possible out of bounds read due to a missing bouEPSS 0.2%CVE-2022-42512MEDIUMIn VsimOperationDataExt::encode of vsimdata.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to loEPSS 0.2%