Fallos del tipo CWE-125
5131 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-85090MEDIUMFreeRDP before 3.31.0 Heap Out-of-Bounds Read via AVC444EPSS 0.4%CVE-2023-42072LOWPDF-XChange Editor JPC File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-6610HIGHKernel: oob access in smb2_dump_detailEPSS 0.4%CVE-2023-42081LOWPDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-14647MEDIUMonnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-boundsEPSS 0.4%CVE-2023-42049LOWPDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-48682MEDIUMFastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, aftEPSS 0.4%CVE-2023-42066LOWPDF-XChange Editor J2K File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-20948HIGHIn dropFramesUntilIframe of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remoEPSS 0.4%CVE-2026-84449LOWlibheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGVEPSS 0.4%CVE-2026-84543HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, EPSS 0.4%CVE-2023-29383—In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is noEPSS 0.4%CVE-2026-45382MEDIUMlibde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometryEPSS 0.4%CVE-2018-16885MEDIUMA flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buEPSS 0.4%CVE-2021-39252MEDIUMA crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.EPSS 0.4%CVE-2026-45383MEDIUMlibde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18EPSS 0.4%CVE-2026-30802HIGHOut-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.EPSS 0.4%CVE-2026-57235MEDIUMNokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`EPSS 0.4%CVE-2022-25749HIGHTransient Denial-of-Service in WLAN due to buffer over-read while parsing MDNS frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.4%CVE-2026-16002HIGHOut-of-bounds Read in MZ Automation lib60870EPSS 0.4%