Weaknesses of type CWE-125

5,207 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2025-23418LOWArkcompiler Ets Runtime has an out-of-bounds read vulnerabilityEPSS 0.1%CVE-2025-22443LOWArkcompiler Ets Runtime has an out-of-bounds read vulnerabilityEPSS 0.1%CVE-2025-22847LOWArkcompiler Ets Runtime has an out-of-bounds read vulnerabilityEPSS 0.1%CVE-2025-20021LOWArkcompiler Ets Runtime has an out-of-bounds read vulnerabilityEPSS 0.1%CVE-2026-14063MEDIUMOut of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive informatioEPSS 0.1%CVE-2026-86564LOWDpdk: dpdk: missing length validation before reading command_data in virtio-net control queue handlerEPSS 0.1%CVE-2025-21089LOWArkcompiler Ets Runtime has an out-of-bounds read vulnerabilityEPSS 0.1%CVE-2025-22841LOWArkcompiler Ets Runtime has an out-of-bounds read vulnerabilityEPSS 0.1%CVE-2026-17572MEDIUMHDF5 SOHM List Index Heap Buffer OverflowEPSS 0.1%CVE-2026-71222MEDIUMGfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processingEPSS 0.1%CVE-2026-23717HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applicEPSS 0.1%CVE-2025-64506MEDIUMLIBPNG is vulnerable to a heap buffer over-read in `png_write_image_8bit` with grayscale+alpha or RGB/RGBA imagesEPSS 0.1%CVE-2026-23716HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applicEPSS 0.1%CVE-2025-61691HIGHVT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability. If the product uses a specially crafted file, arbitrary code EPSS 0.1%CVE-2026-42476MEDIUMTwo heap-based out-of-bounds read vulnerabilities in the STL ASCII file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 exist in RWStl_REPSS 0.1%CVE-2026-17042HIGHPower System Out-of-bounds ReadEPSS 0.1%CVE-2026-76924MEDIUMOut-of-bounds Read in WiresharkEPSS 0.1%CVE-2023-20988MEDIUMIn btm_read_rssi_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local infoEPSS 0.1%CVE-2026-1765MEDIUMLocalsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and potential information disclosure via crafted mp3 filesEPSS 0.1%CVE-2026-78546MEDIUMOut-of-Bounds ReadEPSS 0.1%