Weaknesses of type CWE-125

5,126 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2023-35629MEDIUMMicrosoft USBHUB 3.0 Device Driver Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-0645MEDIUMOut of Bounds read in libjxlEPSS 0.9%CVE-2025-24055MEDIUMWindows USB Video Class System Driver Information Disclosure VulnerabilityEPSS 0.9%CVE-2024-5497HIGHOut of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage EPSS 0.9%CVE-2023-36728MEDIUMMicrosoft SQL Server Denial of Service VulnerabilityEPSS 0.9%CVE-2023-29461HIGHRockwell Automation Arena Simulation Software Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-30596CRITICALTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function.EPSS 0.9%CVE-2023-29460HIGHRockwell Automation Arena Simulation Software Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-38102MEDIUMWindows Layer-2 Bridge Network Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2024-38101MEDIUMWindows Layer-2 Bridge Network Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2026-5314MEDIUMNothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-boundsEPSS 0.8%CVE-2026-5315MEDIUMNothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-boundsEPSS 0.8%CVE-2023-4458MEDIUMKernel: ksmbd: smb2_open out-of-bounds read information disclosure vulnerabilityEPSS 0.8%CVE-2022-23574HIGHOut of bounds read and write in TensorflowEPSS 0.8%CVE-2022-23560HIGHRead and Write outside of bounds in TFLiteEPSS 0.8%CVE-2025-2784HIGHLibsoup: heap buffer over-read in `skip_insignificant_space` when sniffing contentEPSS 0.8%CVE-2019-13512—Fuji Electric FRENIC Loader 3.5.0.0 and prior is vulnerable to an out-of-bounds read vulnerability, which may allow an attacker to read limiEPSS 0.8%CVE-2026-2704MEDIUMOpen Babel CIF File transform3d.cpp DescribeAsString out-of-boundsEPSS 0.8%CVE-2024-47778MEDIUMGHSL-2024-258: GStreamer has an OOB-read in gst_wavparse_adtl_chunkEPSS 0.8%CVE-2026-7568MEDIUMSigned integer overflow in metaphone()EPSS 0.8%