Fallos del tipo CWE-125
5136 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-56378MEDIUMImageMagick - Heap Out-of-Bounds Read in PCD DecoderEPSS 0.4%CVE-2026-87824HIGHzstd-jni 1.3.3-1 through 1.5.7-13 Out-of-Bounds Read via Zstd.trainFromBufferDirectEPSS 0.4%CVE-2026-28979MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7EPSS 0.4%CVE-2026-43703MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS SonoEPSS 0.4%CVE-2026-41069MEDIUMlibheif allows Out-of-bounds vector access leading to invalid dereference (DoS)EPSS 0.4%CVE-2026-34971CRITICALWasmtime miscompiled guest heap access enables sandbox escape on aarch64 CraneliftEPSS 0.4%CVE-2026-12478MEDIUMLibsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)EPSS 0.4%CVE-2026-82066MEDIUMHeap Out-of-Bounds Read in MongoDB Server Query Planning ComponentEPSS 0.4%CVE-2026-14740CRITICALDBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL commentEPSS 0.4%CVE-2026-35201MEDIUMDiscount has an Out-of-bounds Read in rdiscountEPSS 0.4%CVE-2023-0972CRITICALBuffer overflow in S0 Decryption on Z/IP GatweayEPSS 0.4%CVE-2026-0708HIGHLibucl: libucl: denial of service via embedded null byte in ucl inputEPSS 0.4%CVE-2023-25658HIGHTensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGradEPSS 0.4%CVE-2026-12891MEDIUMGstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parserEPSS 0.4%CVE-2023-37353LOWKofax Power PDF JPG File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2023-37356LOWKofax Power PDF GIF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-65365MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.4%CVE-2025-0518MEDIUMUnchecked sscanf return value which leads to memory data leakEPSS 0.4%CVE-2022-42399HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2023-37351LOWKofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%