Weaknesses of type CWE-125
5,213 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2025-46280MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpeEPSS 0.1%CVE-2023-49602LOWArkui has a type confusion vulnerabilityEPSS 0.1%CVE-2026-70598LOWElectron: Off-screen rendering trusts GPU-supplied geometry over shared-memory sizeEPSS 0.1%CVE-2026-47513HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-boundsEPSS 0.1%CVE-2026-21489MEDIUMiccDEV has Out-of-bounds Read and Integer Underflow (Wrap or Wraparound)EPSS 0.1%CVE-2022-32602MEDIUMIn keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with noEPSS 0.1%CVE-2026-16891LOWVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.1%CVE-2026-26054MEDIUMSumatraPDF: Heap out-of-bounds read in MOBI header parser.EPSS 0.1%CVE-2026-24915MEDIUMOut-of-bounds read issue in the media subsystem.
Impact: Successful exploitation of this vulnerability will affect availability and confidenEPSS 0.1%CVE-2020-8939MEDIUMOut of Bounds read in AsyloEPSS 0.1%CVE-2020-8936MEDIUMArbitrary enclave memory overwrite vulnerability in ECall ecall_restoreEPSS 0.1%CVE-2026-24225MEDIUMNVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A suEPSS 0.1%CVE-2025-54647MEDIUMOut-of-bounds read vulnerability in the SSAP module of the NearLink protocol stack.
Impact: Successful exploitation of this vulnerability maEPSS 0.1%CVE-2026-42479MEDIUMAn out-of-bounds read vulnerability in VrmlData_IndexedLineSet::TShape in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allowEPSS 0.1%CVE-2026-20786MEDIUMOut-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. UnprivilegedEPSS 0.1%CVE-2026-68743MEDIUMSssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1EPSS 0.1%CVE-2026-4159LOWwc_PKCS7_DecodeEnvelopedData 1 byte out-of-bounds readEPSS 0.1%CVE-2024-33607MEDIUMOut-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enabEPSS 0.1%CVE-2025-23274MEDIUMNVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a maliciously crafted inpuEPSS 0.1%CVE-2026-47544HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds rEPSS 0.1%