Weaknesses of type CWE-125

5,128 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2026-70124MEDIUMWindows DHCP Server Information Disclosure VulnerabilityEPSS 0.8%CVE-2025-21227MEDIUMWindows Digital Media Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2025-21258MEDIUMWindows Digital Media Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-69929MEDIUMWindows DHCP Server Information Disclosure VulnerabilityEPSS 0.8%CVE-2025-21255MEDIUMWindows Digital Media Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2022-20606MEDIUMIn SAEMM_MiningCodecTableWithMsgIE of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This EPSS 0.8%CVE-2024-47774MEDIUMGHSL-2024-262: GStreamer has an OOB-read in gst_avi_subtitle_parse_gab2_chunkEPSS 0.8%CVE-2020-6976—Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user openEPSS 0.8%CVE-2024-22040HIGHA vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions),EPSS 0.8%CVE-2020-10637—Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A EPSS 0.8%CVE-2020-7853MEDIUMTOBESOFT XPLATFORM Out-of-Bounds Read/Write VulnerabilitiesEPSS 0.8%CVE-2022-43612LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.EPSS 0.8%CVE-2018-19020—When CX-Supervisor (Versions 3.42 and prior) processes project files and tampers with the value of an offset, an attacker can force the applEPSS 0.8%CVE-2022-43615LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.EPSS 0.8%CVE-2026-42914MEDIUMWindows Kerberos Denial of Service VulnerabilityEPSS 0.8%CVE-2022-43611LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.EPSS 0.8%CVE-2022-21726HIGHOut of bounds read in TensorflowEPSS 0.8%CVE-2023-51589MEDIUMBlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.8%CVE-2026-39979MEDIUMjq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted BuffersEPSS 0.8%CVE-2023-33139MEDIUMVisual Studio Information Disclosure VulnerabilityEPSS 0.8%