Weaknesses of type CWE-125

5,159 results

Leitura fora dos limites de memória

Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.

Example

Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.

How to mitigate

Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.

CVE-2026-32605HIGHNimiq: Remote crash via off-by-one signer bounds check in proposal bufferEPSS 0.6%CVE-2026-90560HIGHzstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictDecompressEPSS 0.6%CVE-2024-25178CRITICALLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.EPSS 0.6%CVE-2025-54950CRITICALAn out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execEPSS 0.6%CVE-2022-28312LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16EPSS 0.6%CVE-2021-42722HIGHAdobe Bridge Out-of-bounds read could lead to Arbitrary Code ExecutionEPSS 0.6%CVE-2022-28308LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.16.02.022. User inEPSS 0.6%CVE-2022-28309LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.16.02.022. User inEPSS 0.6%CVE-2022-28313LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16EPSS 0.6%CVE-2023-2512MEDIUMBuffer under-read in workerdEPSS 0.6%CVE-2021-46749HIGHInsufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox EPSS 0.6%CVE-2022-35703HIGHAdobe Bridge SVG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.6%CVE-2021-46765HIGHInsufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potenEPSS 0.6%CVE-2022-35702HIGHAdobe Bridge SVG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.6%CVE-2021-46794HIGHInsufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox EPSS 0.6%CVE-2022-36053MEDIUMOut-of-bounds read in the uIP buffer moduleEPSS 0.6%CVE-2023-6387HIGHIncorrect buffer parsing in Bluetooth LE sample code may lead to buffer overflowEPSS 0.6%CVE-2026-2771CRITICALUndefined behavior in the DOM: Core & HTML componentEPSS 0.6%CVE-2023-36201—An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted script to the arrays.EPSS 0.6%CVE-2022-28645LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16EPSS 0.6%