Weaknesses of type CWE-125
5,159 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2026-85444HIGHMOOS-IvP through 24.8.1 Out-of-Bounds Read in isBraced, isQuoted and isChevronedEPSS 0.6%CVE-2026-67857HIGHopen62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.EPSS 0.6%CVE-2026-27880HIGHOpenFeature evaluation API reads input data with no boundsEPSS 0.6%CVE-2026-46600HIGHParsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessageEPSS 0.6%CVE-2021-31354HIGHJunos OS and Junos OS Evolved: A vulnerability in the Juniper Agile License Client may allow an attacker to perform Remote Code Execution (RCE)EPSS 0.6%CVE-2022-47630HIGHTrusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of gEPSS 0.6%CVE-2024-27282MEDIUMAn issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extraEPSS 0.6%CVE-2026-92240CRITICALOut-of-bounds read in IMAP response parserEPSS 0.6%CVE-2024-56627HIGHksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_readEPSS 0.6%CVE-2026-52719HIGHGstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment length validation in va decoderEPSS 0.6%CVE-2025-0908LOWPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.6%CVE-2022-39392MEDIUMWasmtime vulnerable to out of bounds read/write with zero-memory-pages configurationEPSS 0.6%CVE-2026-90775HIGHPostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule WeightEPSS 0.6%CVE-2024-56378MEDIUMlibpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.EPSS 0.6%CVE-2022-31812HIGHA vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications contain an out of bounds EPSS 0.6%CVE-2026-78049MEDIUMSysterel S2OPC AddNodes Service sopc_node_mgt_helper_internal.c out-of-boundsEPSS 0.6%CVE-2021-42374MEDIUMAn out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is EPSS 0.6%CVE-2025-30174HIGHA vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < VEPSS 0.6%CVE-2025-30176HIGHA vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < VEPSS 0.6%CVE-2025-64656CRITICALAzure Application Gateway Elevation of Privilege VulnerabilityEPSS 0.6%