Weaknesses of type CWE-125
5,207 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-47576HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module through which an attacker might initiate an out-of-boundEPSS 0.1%CVE-2025-37149MEDIUMA potential
out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.EPSS 0.1%CVE-2023-20958HIGHIn read_paint of ttcolr.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information discloEPSS 0.1%CVE-2026-23865MEDIUMAn integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an EPSS 0.1%CVE-2026-103641MEDIUMGegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoderEPSS 0.1%CVE-2026-20490MEDIUMIn ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actEPSS 0.1%CVE-2024-32915MEDIUMIn CellInfoListParserV2::FillCellInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. ThiEPSS 0.1%CVE-2023-25546LOWOut-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via locEPSS 0.1%CVE-2026-23718HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applicEPSS 0.1%CVE-2026-12444MEDIUMOut of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain potentially sensitivEPSS 0.1%CVE-2026-42480MEDIUMA stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 aEPSS 0.1%CVE-2026-48770MEDIUMNotepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crashEPSS 0.1%CVE-2026-3508MEDIUMAn Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) vEPSS 0.1%CVE-2026-47524MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-boEPSS 0.1%CVE-2026-47527MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds readEPSS 0.1%CVE-2025-54648MEDIUMOut-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack.
Impact: Successful exploitation of this vulnerability maEPSS 0.1%CVE-2026-42481MEDIUMOpen CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple vulnerabilities in its IGES and STEP file parsers that can be triggered by craftEPSS 0.1%CVE-2025-54080LOWExiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS fileEPSS 0.1%CVE-2026-47515MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-boundsEPSS 0.1%CVE-2025-20724MEDIUMIn wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure EPSS 0.1%