Weaknesses of type CWE-125
5,207 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2025-40740HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of boundEPSS 0.2%CVE-2022-41577HIGHThe kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this EPSS 0.1%CVE-2026-43767MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. AEPSS 0.1%CVE-2026-49509MEDIUMOut-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers.
This issue affects rLottie: 25648aef19187b3f87f4d94EPSS 0.1%CVE-2025-39840HIGHaudit: fix out-of-bounds read in audit_compare_dname_path()EPSS 0.1%CVE-2023-28074MEDIUMDell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains aEPSS 0.1%CVE-2026-11743MEDIUMMissing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and writeEPSS 0.1%CVE-2026-20496MEDIUMIn geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malEPSS 0.1%CVE-2024-8159MEDIUMDeep Freeze 9.00.020.5760 - Out-of-bounds readEPSS 0.1%CVE-2026-90463MEDIUMSssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)EPSS 0.1%CVE-2025-43205MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, mEPSS 0.1%CVE-2026-35233MEDIUMAn unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-leveEPSS 0.1%CVE-2026-12232MEDIUMOut-of-bounds read via unvalidated stream_id in Intel ALH DAI get_propertiesEPSS 0.1%CVE-2023-43756LOWDsoftbus has an out-of-bounds read vulnerabilityEPSS 0.1%CVE-2026-21365MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.1%CVE-2025-39922HIGHixgbe: fix incorrect map used in eee linkmodeEPSS 0.1%CVE-2025-70330LOWEasy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific fields EPSS 0.1%CVE-2026-73434MEDIUMGstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsingEPSS 0.1%CVE-2023-49118LOWDsoftbus has an out-of-bounds read vulnerabilityEPSS 0.1%CVE-2025-22842LOWarkcompiler_ets_runtime has an out-of-bounds read vulnerabilityEPSS 0.1%