Weaknesses of type CWE-125

5,217 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2025-11775MEDIUMAn out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crEPSS 0.1%CVE-2022-20609MEDIUMIn Pixel cellular firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclEPSS 0.1%CVE-2022-20608MEDIUMIn Pixel cellular firmware, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information diEPSS 0.1%CVE-2022-20527MEDIUMIn HalCoreCallback of halcore.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local informationEPSS 0.1%CVE-2026-33968LOWAn issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driveEPSS 0.1%CVE-2025-32007MEDIUMOut-of-bounds read for some TDX before version tdx module 1.5.24 within Ring 0: Hypervisor may allow an information disclosure. Authorized aEPSS 0.1%CVE-2024-20022MEDIUMIn lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with SystEPSS 0.1%CVE-2022-20528LOWIn findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%CVE-2026-46690MEDIUMunbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX raceEPSS 0.1%CVE-2024-25988HIGHIn SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead toEPSS 0.1%CVE-2025-9032HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed PE fileEPSS 0.1%CVE-2022-25665MEDIUMInformation disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon MobileEPSS 0.1%CVE-2026-56136MEDIUMIn NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly EPSS 0.1%CVE-2025-9033HIGHAvira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 3)EPSS 0.1%CVE-2026-19086LOWIBM i is Affected By Multiple Vulnerabilities in PASE [, ]EPSS 0.1%CVE-2026-10267MEDIUMjanet-lang janet debug.c doframe out-of-boundsEPSS 0.1%CVE-2026-75147MEDIUMFFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.cEPSS 0.1%CVE-2022-42774MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2024-27223MEDIUMIn EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check.EPSS 0.1%CVE-2022-39130MEDIUMIn face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in EPSS 0.1%