Weaknesses of type CWE-125

5,209 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2026-1765MEDIUMLocalsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and potential information disclosure via crafted mp3 filesEPSS 0.1%CVE-2023-20988MEDIUMIn btm_read_rssi_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local infoEPSS 0.1%CVE-2025-20693MEDIUMIn wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) iEPSS 0.1%CVE-2025-40811HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update EPSS 0.1%CVE-2026-24873HIGHOut-of-bounds read in lpp-vitaEPSS 0.1%CVE-2026-28890MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpectedEPSS 0.1%CVE-2025-40812HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update EPSS 0.1%CVE-2025-8298LOWRealtek RTL8811AU rtwlanu.sys N6CQueryInformationHandleCustomized11nOids Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.1%CVE-2025-29871LOWFile Station 5EPSS 0.1%CVE-2018-9481MEDIUMIn bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote infoEPSS 0.1%CVE-2026-76882MEDIUMOut-of-bounds Read in WiresharkEPSS 0.1%CVE-2026-15030MEDIUMOut-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administratoEPSS 0.1%CVE-2026-76923MEDIUMOut-of-bounds Read in WiresharkEPSS 0.1%CVE-2022-20471MEDIUMIn SendIncDecRestoreCmdPart2 of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to loEPSS 0.1%CVE-2022-32595MEDIUMIn widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with SEPSS 0.1%CVE-2025-23286MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit oEPSS 0.1%CVE-2025-31354MEDIUMSubnet Solutions PowerSYSTEM Center Out-of-Bounds ReadEPSS 0.1%CVE-2023-49602LOWArkui has a type confusion vulnerabilityEPSS 0.1%CVE-2026-21489MEDIUMiccDEV has Out-of-bounds Read and Integer Underflow (Wrap or Wraparound)EPSS 0.1%CVE-2026-16891LOWVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%