Weaknesses of type CWE-125
5,180 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-9504MEDIUMGNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-boundsEPSS 0.2%CVE-2025-64462HIGHOut-of-Bounds Read in LVResFile::RGetMemFileHandle() in NI LabVIEWEPSS 0.2%CVE-2026-10680HIGHOut-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflowEPSS 0.2%CVE-2025-64466HIGHOut-of-Bounds Read in lvre!ExecPostedProcRecPost() in NI LabVIEWEPSS 0.2%CVE-2026-21348MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-64467HIGHOut-of-Bounds Read in LVResFile::FindRsrcListEntry() in NI LabVIEWEPSS 0.2%CVE-2025-64463HIGHOut-of-Bounds Read in LVResource::DetachResource() in NI LabVIEWEPSS 0.2%CVE-2026-17512MEDIUMggml-org whisper.cpp log_mel_spectrogram out-of-boundsEPSS 0.2%CVE-2026-67550MEDIUMre2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)EPSS 0.2%CVE-2026-11786LOW389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type()EPSS 0.2%CVE-2026-3949MEDIUMstrukturag libheif HEIF File decoder_vvdec.cc vvdec_push_data2 out-of-boundsEPSS 0.2%CVE-2026-90681MEDIUMMatthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-boundsEPSS 0.2%CVE-2026-42326MEDIUMImageMagick: Heap Buffer Over-Read in IPTC encoderEPSS 0.2%CVE-2026-3950MEDIUMstrukturag libheif stsz/stts track.cc load out-of-boundsEPSS 0.2%CVE-2026-9530MEDIUMGNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-boundsEPSS 0.2%CVE-2024-27382MEDIUMAn issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_EPSS 0.2%CVE-2025-23345MEDIUMNVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds readEPSS 0.2%CVE-2026-42771MEDIUMPossible Out of Bounds Read in X509_VERIFY_PARAM_set1_email()EPSS 0.2%CVE-2026-27709MEDIUMNanaZip .NET Single-File Manifest Parser Vulnerable to Out-of-Bounds Read via Unchecked RelativePathLengthEPSS 0.2%CVE-2026-38719MEDIUMOpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonEPSS 0.2%