Weaknesses of type CWE-125
5,180 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-3949MEDIUMstrukturag libheif HEIF File decoder_vvdec.cc vvdec_push_data2 out-of-boundsEPSS 0.2%CVE-2026-38719MEDIUMOpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonEPSS 0.2%CVE-2026-43817MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 2EPSS 0.2%CVE-2026-11786LOW389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type()EPSS 0.2%CVE-2026-90681MEDIUMMatthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-boundsEPSS 0.2%CVE-2026-42771MEDIUMPossible Out of Bounds Read in X509_VERIFY_PARAM_set1_email()EPSS 0.2%CVE-2026-3950MEDIUMstrukturag libheif stsz/stts track.cc load out-of-boundsEPSS 0.2%CVE-2026-9530MEDIUMGNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-boundsEPSS 0.2%CVE-2026-47748MEDIUMstable-diffusion.cpp: Out-of-bounds reads in PyTorch checkpoint pickle opcode parsingEPSS 0.2%CVE-2026-47251MEDIUMlibheif has an incomplete fix for CVE-2026-3949: integer overflow bypass in vvdec_push_data2EPSS 0.2%CVE-2026-7135MEDIUMGPAC MP4Box box_code_base.c elng_box_read out-of-boundsEPSS 0.2%CVE-2023-53420HIGHntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr()EPSS 0.2%CVE-2026-54579LOWmport mirror-selection ping accepts insufficiently validated ICMP repliesEPSS 0.2%CVE-2026-92475MEDIUMGPAC downloader.c wait_for_header_and_parse out-of-boundsEPSS 0.2%CVE-2023-53272HIGHnet: ena: fix shift-out-of-bounds in exponential backoffEPSS 0.2%CVE-2026-65376MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.2%CVE-2024-36054HIGHHw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gaEPSS 0.2%CVE-2026-66151MEDIUMSonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, EPSS 0.2%CVE-2026-28968MEDIUMAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSEPSS 0.2%CVE-2024-38481MEDIUMDell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arEPSS 0.2%