Weaknesses of type CWE-125
5,131 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-24213HIGHNVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successfuEPSS 0.7%CVE-2022-39061MEDIUMChangingTec MegaServiSignAdapter - Out-of-bounds ReadEPSS 0.7%CVE-2024-23086CRITICALApfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this iEPSS 0.7%CVE-2020-28394—A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected appliEPSS 0.7%CVE-2020-27008—A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected appliEPSS 0.7%CVE-2026-7482HIGHOllama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackersEPSS 0.7%CVE-2026-42216HIGHOpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansionEPSS 0.7%CVE-2026-28231MEDIUMpillow_heif Has Integer Overflow in Encode Path Buffer Validation that Leads to Heap Out-of-Bounds ReadEPSS 0.7%CVE-2023-3040LOWOut of Bounds Access Leading to Undefined BehaviorEPSS 0.7%CVE-2024-45829MEDIUMSharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulEPSS 0.7%CVE-2026-67636CRITICALMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-54341HIGHDragonfly: RESTORE operations may crash the serverEPSS 0.7%CVE-2024-20658HIGHMicrosoft Virtual Hard Disk Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-15714MEDIUMLibsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary stringEPSS 0.7%CVE-2025-27788HIGHRuby JSON Parser has Out-of-bounds ReadEPSS 0.7%CVE-2023-2838MEDIUMOut-of-bounds Read in gpac/gpacEPSS 0.7%CVE-2026-20479HIGHIn Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has conEPSS 0.7%CVE-2024-21430MEDIUMWindows USB Attached SCSI (UAS) Protocol Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-44648MEDIUMAn Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive infEPSS 0.7%CVE-2022-44647MEDIUMAn Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive infEPSS 0.7%