Weaknesses of type CWE-125
5,216 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2025-23274MEDIUMNVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a maliciously crafted inpuEPSS 0.1%CVE-2025-7003HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 1)EPSS 0.1%CVE-2026-76929MEDIUMOut-of-bounds Read in WiresharkEPSS 0.1%CVE-2017-13318MEDIUMIn HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remoEPSS 0.1%CVE-2026-94282MEDIUMOut-of-bounds read in libXi's XI2 enter/leave/focus cookie conversionEPSS 0.1%CVE-2026-81882LOWradare2: Missing string termination causes heap out-of-bounds read in radare2 bplist parserEPSS 0.1%CVE-2026-24820MEDIUMA stack overflow vulnerability in turanszkij/WickedEngineEPSS 0.1%CVE-2022-32641MEDIUMIn meta wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with SyEPSS 0.1%CVE-2017-13317MEDIUMIn HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could EPSS 0.1%CVE-2026-81881LOWradare2: Heap out-of-bounds read in radare2 Mach-O Swift metadata parserEPSS 0.1%CVE-2025-7017HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed Windows MSI fileEPSS 0.1%CVE-2026-91786MEDIUMGnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer sizeEPSS 0.1%CVE-2026-22801MEDIUMLIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*EPSS 0.1%CVE-2026-73583MEDIUMSblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdrEPSS 0.1%CVE-2025-7002HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 2)EPSS 0.1%CVE-2026-68742MEDIUMSssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddrEPSS 0.1%CVE-2025-23235LOWarkcompiler_ets_runtime has an out-of-bounds write vulnerabilityEPSS 0.1%CVE-2026-40144HIGHMemory corruption vulnerability in Endpoint Privilege Management (Windows deployments)EPSS 0.1%CVE-2026-79516MEDIUMAn out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of SEPSS 0.1%CVE-2026-102820MEDIUMpageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)EPSS 0.1%