Fallos del tipo CWE-125
5134 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2025-51602MEDIUMmmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMEPSS 0.4%CVE-2026-69345MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-27163MEDIUMAcrobat Reader | Out-of-bounds Read (CWE-125)EPSS 0.4%CVE-2026-69308MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-69367MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-68881MEDIUMMicrosoft Standard XPS Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-69303MEDIUMPush Message Routing Service Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-5873HIGHOut of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2024-51562MEDIUMbhyve(8) nvme_opc_get_log_page buffer over-readEPSS 0.4%CVE-2023-43692HIGHAn issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). Out-of-bound reads in striEPSS 0.4%CVE-2025-53859MEDIUMNGINX ngx_mail_smtp_module vulnerabilityEPSS 0.4%CVE-2025-55086MEDIUMIn NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked indEPSS 0.4%CVE-2026-44041MEDIUMUltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminatedEPSS 0.4%CVE-2025-47112MEDIUMAcrobat Reader | Out-of-bounds Read (CWE-125)EPSS 0.4%CVE-2026-9928HIGHOut of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crEPSS 0.4%CVE-2026-82072HIGHOut of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via EPSS 0.4%CVE-2026-15903HIGHOut of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.4%CVE-2026-78978HIGHOut of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitraryEPSS 0.4%CVE-2026-87440HIGHOut of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox vEPSS 0.4%CVE-2024-29948LOWThere is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending sEPSS 0.4%