Fallos del tipo CWE-125
5136 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-45681MEDIUMOpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB sizeEPSS 0.4%CVE-2025-48816HIGHHID Class Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-67306MEDIUMFreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLEEPSS 0.4%CVE-2025-47996HIGHWindows MBT Transport Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-45608MEDIUMWindows DHCP Client Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-27345LOWKofax Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-5307LOWKofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2022-42402HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is reEPSS 0.4%CVE-2023-48635MEDIUMZDI-CAN-22174: Adobe After Effects AEP File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-7425MEDIUMOut-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCPEPSS 0.4%CVE-2025-37178MEDIUMOut-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating SystemEPSS 0.4%CVE-2026-10848HIGHOut-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)EPSS 0.4%CVE-2022-41883MEDIUMOut of bounds segmentation fault due to unequal op inputs in TensorflowEPSS 0.4%CVE-2026-50735MEDIUMpglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copyinEPSS 0.4%CVE-2026-32738MEDIUMlibheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunkEPSS 0.4%CVE-2026-42799HIGHOut-of-bounds read in ulpEPSS 0.4%CVE-2023-36629MEDIUMThe ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.EPSS 0.4%CVE-2026-12087CRITICALSocket versions before 2.041 for Perl have an out-of-bounds heap readEPSS 0.4%CVE-2026-28532MEDIUMFRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser FunctionsEPSS 0.4%CVE-2024-24452MEDIUMAn invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attacEPSS 0.4%