Weaknesses of type CWE-125

5,226 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2024-47028MEDIUMIn ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosuEPSS 0.1%CVE-2025-36921MEDIUMIn ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could leadEPSS 0.1%CVE-2024-47026MEDIUMIn gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local informatioEPSS 0.1%CVE-2026-0131HIGHIn RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privEPSS 0.1%CVE-2024-47034MEDIUMthere is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional exeEPSS 0.1%CVE-2024-47029MEDIUMIn TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible out of bounds read dueEPSS 0.1%CVE-2026-25258HIGHOut-of-bounds Read in DSP ServiceEPSS 0.1%CVE-2026-25282HIGHOut-of-bounds Read in OOBMEPSS 0.1%CVE-2026-44038MEDIUMGlobal buffer out-of-bounds read in DCMTK JPEG Huffman decodingEPSS —CVE-2026-12091LOWSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS —CVE-2026-106428MEDIUMOut-of-bounds read in SCRAM response parsing in MongoDB C DriverEPSS —CVE-2026-107611HIGHOut-of-bounds read in TightVNC Viewer ZRLE palette decodingEPSS —CVE-2026-16177MEDIUMIBM DataPower Gateway Out-of-bounds ReadEPSS —CVE-2026-16161HIGHIBM DataPower Gateway Out-of-bounds ReadEPSS —CVE-2026-14496HIGHIBM DataPower Gateway Out-of-bounds ReadEPSS —CVE-2026-106435MEDIUMApplication denial of service via out-of-bounds read in BSON Regex decoding in MongoDB Python DriverEPSS —CVE-2026-7826HIGHHeap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDBEPSS —CVE-2026-14988MEDIUMIBM DataPower Gateway Out-of-bounds ReadEPSS —CVE-2026-107729MEDIUMSumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes out-of-bounds readEPSS —CVE-2026-107738MEDIUMSumatraPDF: Untrusted binary record offset used without lower-bound validationEPSS —