Weaknesses of type CWE-125
5,225 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2023-20727MEDIUMIn wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System eEPSS 0.1%CVE-2025-54637MEDIUMOut-of-bounds array access issue due to insufficient data verification in the kernel ambient light module.
Impact: Successful exploitation oEPSS 0.1%CVE-2023-20729MEDIUMIn wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System eEPSS 0.1%CVE-2023-20730MEDIUMIn wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System eEPSS 0.1%CVE-2023-20818MEDIUMIn wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure wiEPSS 0.1%CVE-2023-20742MEDIUMIn ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System exEPSS 0.1%CVE-2024-22007MEDIUMIn constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disEPSS 0.1%CVE-2023-20675MEDIUMIn wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System eEPSS 0.1%CVE-2023-20674MEDIUMIn wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System eEPSS 0.1%CVE-2022-47334MEDIUMIn phasecheck server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with EPSS 0.1%CVE-2023-35657MEDIUMIn bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information dEPSS 0.1%CVE-2023-21025MEDIUMIn ufdt_local_fixup_prop of ufdt_overlay.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to locaEPSS 0.1%CVE-2023-20679MEDIUMIn wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System EPSS 0.1%CVE-2023-20676MEDIUMIn wlan, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System eEPSS 0.1%CVE-2023-20688MEDIUMIn power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System EPSS 0.1%CVE-2023-21014MEDIUMIn multiple locations of p2p_iface.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local inforEPSS 0.1%CVE-2023-20741MEDIUMIn ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System exEPSS 0.1%CVE-2022-48236MEDIUMIn MP3 encoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with SystemEPSS 0.1%CVE-2023-21013MEDIUMIn forceStaDisconnection of hostapd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local infoEPSS 0.1%CVE-2023-20665MEDIUMIn ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System exEPSS 0.1%