Weaknesses of type CWE-125
5,225 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2025-27708MEDIUMOut-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel mayEPSS 0.1%CVE-2026-11389MEDIUMOut-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.1%CVE-2026-102757HIGHAn unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode,EPSS 0.1%CVE-2025-27940MEDIUMOut-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Software side chEPSS 0.1%CVE-2026-18626MEDIUMOut-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.1%CVE-2025-29937MEDIUMAn out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory loEPSS 0.1%CVE-2026-18458MEDIUMOut-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.1%CVE-2025-36918HIGHIn aoc_service_read_message of aoc_ipc_core.c, there is a possible out of bounds read due to improper input validation. This could lead to lEPSS 0.1%CVE-2026-94284MEDIUMOut-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parserEPSS 0.1%CVE-2023-20840MEDIUMIn imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of prEPSS 0.1%CVE-2026-10305MEDIUMOut-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers.
This issue affects rlottie: before 223a2a41ba4f462EPSS 0.1%CVE-2024-20093MEDIUMIn vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System eEPSS 0.1%CVE-2026-0135HIGHIn Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no additional EPSS 0.1%CVE-2022-27832MEDIUMImproper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a craftedEPSS 0.1%CVE-2018-9464HIGHIn multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalatioEPSS 0.1%CVE-2023-20848MEDIUMIn imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privileEPSS 0.1%CVE-2025-31937MEDIUMOut-of-bounds read for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of serviEPSS 0.1%CVE-2024-20107MEDIUMIn da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additioEPSS 0.1%CVE-2023-42726MEDIUMIn TeleService, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with SystemEPSS 0.1%CVE-2026-56978HIGHIn get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalEPSS 0.1%