Weaknesses of type CWE-125

5,130 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2022-1452HIGHOut-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in radareorg/radare2EPSS 0.8%CVE-2023-46045HIGHGraphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon becausEPSS 0.8%CVE-2024-26000MEDIUMPHOENIX CONTACT: Out of bounds read only memory accessEPSS 0.8%CVE-2023-51592MEDIUMBlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.8%CVE-2022-43610LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Corel CorelDRAW Graphics Suite 23.EPSS 0.8%CVE-2024-32301CRITICALTenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.EPSS 0.8%CVE-2024-30630CRITICALTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function.EPSS 0.8%CVE-2024-30587CRITICALTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.EPSS 0.8%CVE-2024-43538MEDIUMWindows Mobile Broadband Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2024-43537MEDIUMWindows Mobile Broadband Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2024-43542MEDIUMWindows Mobile Broadband Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2024-43540MEDIUMWindows Mobile Broadband Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2020-10597—Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processinEPSS 0.8%CVE-2026-43618MEDIUMRsync < 3.4.3 Integer Overflow Information DisclosureEPSS 0.8%CVE-2025-27741HIGHNTFS Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-33599LOWOut-of-bounds read in service discoveryEPSS 0.8%CVE-2023-47456CRITICALTenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat.EPSS 0.8%CVE-2024-12055HIGHDoS using malicious gguf model file in ollama/ollamaEPSS 0.8%CVE-2025-58050MEDIUMPCRE2: heap-buffer-overflow read in match_ref due to missing boundary restoration in SCSEPSS 0.8%CVE-2024-23264MEDIUMA validation issue was addressed with improved input sanitization. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS EPSS 0.8%