Weaknesses of type CWE-125
5,224 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-91810MEDIUMFoxit PDF Editor/Reader Doc Object Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-91807MEDIUMFoxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-18857LOWThis Power System update is being released to addressEPSS 0.1%CVE-2026-91808MEDIUMFoxit PDF Editor/Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-13478MEDIUMOut-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_blocks_countEPSS 0.1%CVE-2026-91817MEDIUMFoxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.1%CVE-2026-104042MEDIUMSssd: sssd: denial of service via out-of-bounds read in pam responderEPSS 0.1%CVE-2024-20058MEDIUMIn keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with SyEPSS 0.1%CVE-2023-21206—In initiateVenueUrlAnqpQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could leadEPSS 0.1%CVE-2023-32878MEDIUMIn battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with SEPSS 0.1%CVE-2026-10998MEDIUMOut of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of boEPSS 0.1%CVE-2025-27708MEDIUMOut-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel mayEPSS 0.1%CVE-2024-25992HIGHIn tmu_tz_control of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of priEPSS 0.1%CVE-2023-20719MEDIUMIn pqframework, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with SEPSS 0.1%CVE-2026-31912MEDIUMOOBR in libpcap before 1.10.7EPSS 0.1%CVE-2026-106061MEDIUMGimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted fileEPSS 0.1%CVE-2018-9383MEDIUMIn asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local informEPSS 0.1%CVE-2026-79616LOWOut-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt QuickEPSS 0.1%CVE-2026-77797LOWVelociraptor Prefetch parser out of boundsEPSS 0.1%CVE-2026-61862LOWImageMagick before 7.1.2-26 Information Disclosure via identifyEPSS 0.1%