Weaknesses of type CWE-125
5,180 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-84565HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.2%CVE-2026-43747HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TEPSS 0.2%CVE-2026-43738MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS GoEPSS 0.2%CVE-2024-27381MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2025-20101MEDIUMOut-of-bounds read for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable information disclosure or denialEPSS 0.2%CVE-2026-58087HIGHHeap out-of-bounds access in semctl(2)EPSS 0.2%CVE-2024-47940HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of boundEPSS 0.2%CVE-2026-64776MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An EPSS 0.2%CVE-2025-65087HIGHOut-of-bounds read in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt ShareEPSS 0.2%CVE-2025-65088HIGHOut-of-bounds read in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt ShareEPSS 0.2%CVE-2024-27380MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2024-22273HIGHThe storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access tEPSS 0.2%CVE-2026-39956MEDIUMjq: Missing runtime type checks for _strindices lead to crash and limited memory disclosureEPSS 0.2%CVE-2024-47941HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of boundEPSS 0.2%CVE-2026-64692HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOEPSS 0.2%CVE-2026-62291MEDIUMlibheif: Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensionsEPSS 0.2%CVE-2026-20488MEDIUMIn display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a mEPSS 0.2%CVE-2026-20489MEDIUMIn display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a maliEPSS 0.2%CVE-2026-38973MEDIUMmrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method().EPSS 0.2%CVE-2024-1140MEDIUMTwister Antivirus v8.17 - Out-of-bounds ReadEPSS 0.2%