Weaknesses of type CWE-125
5,216 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-102820MEDIUMpageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)EPSS 0.1%CVE-2026-105838MEDIUMlibmikmod before 3.3.14 Heap Out-of-Bounds Read via IT Module LoaderEPSS 0.1%CVE-2024-36502HIGHOut-of-bounds read vulnerability in the audio module
Impact: Successful exploitation of this vulnerability will affect availability.EPSS 0.1%CVE-2026-77219MEDIUMGNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image LoaderEPSS 0.1%CVE-2026-56361MEDIUMImageMagick - Heap Buffer Overflow via Off-by-One in Morphology ProcessingEPSS 0.1%CVE-2023-31330LOWAn out-of-bounds read in the ASP could allow a privileged attacker with access to a malicious bootloader to potentially read sensitive memorEPSS 0.1%CVE-2026-16234HIGHOut-of-Bounds Read Vulnerability in NI LabVIEW when loading VIEPSS 0.1%CVE-2026-33962LOWAn issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink cEPSS 0.1%CVE-2026-20609MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS EPSS 0.1%CVE-2026-47520HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds rEPSS 0.1%CVE-2026-47499HIGHNVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a guest could cause an out-of-EPSS 0.1%CVE-2026-47519HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds rEPSS 0.1%CVE-2026-47535HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A suEPSS 0.1%CVE-2026-47592HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an EPSS 0.1%CVE-2026-47521HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds rEPSS 0.1%CVE-2026-47536HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds rEPSS 0.1%CVE-2026-73067MEDIUMTesseract: Heap OOB read in the DAWG loaderEPSS 0.1%CVE-2026-47166MEDIUMImageMagick: Heap Buffer Over-Read in distributed pixel cache serverEPSS 0.1%CVE-2026-81646MEDIUMOut-of-bounds read vulnerability in the graphics module.
Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-62862MEDIUMAmpere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorreEPSS 0.1%