Weaknesses of type CWE-125

5,219 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2026-0106CRITICALIn vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%CVE-2022-42773MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-102567MEDIUMCTranslate2 before 4.8.1 Out-of-Bounds Read via Model DeserializationEPSS 0.1%CVE-2026-49314HIGHOOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availabiliEPSS 0.1%CVE-2022-42761MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-65122MEDIUMNVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lEPSS 0.1%CVE-2026-20751HIGHOut-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers EPSS 0.1%CVE-2025-41278HIGHNozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackEPSS 0.1%CVE-2026-20518MEDIUMIn geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if aEPSS 0.1%CVE-2023-43694MEDIUMAn issue was discovered in Malwarebytes 4.6.14.326 and before and 5.1.5.116 and before (and Nebula 2020-10-21 and later). An Out of bounds rEPSS 0.1%CVE-2026-88835MEDIUMBusybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packagesEPSS 0.1%CVE-2026-104030MEDIUMSssd: sssd: denial of service via out-of-bounds read during passkey parsingEPSS 0.1%CVE-2026-75819LOWOut-of-bounds Read in GNU AspellEPSS 0.1%CVE-2026-2243MEDIUMQemu-kvm: heap buffer out-of-bounds read in vmdk compressed grain parsingEPSS 0.1%CVE-2026-19029MEDIUMHDF5 scale-offset filter heap buffer over-read via crafted chunkEPSS 0.1%CVE-2022-42769LOWIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2026-100505MEDIUMGhidra 9.2 through 12.1.4 Heap Out-of-Bounds Read via StringManagerEPSS 0.1%CVE-2022-44440MEDIUMIn wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2022-44442MEDIUMIn wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.EPSS 0.1%CVE-2022-44441MEDIUMIn wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.EPSS 0.1%