Fallos del tipo CWE-125
5159 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2024-39393HIGHAdobe Indesign 2024 PCT File Parsing Memory Corruption Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-42413LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.3%CVE-2023-26354MEDIUMZDI-CAN-19519: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-26351MEDIUMZDI-CAN-19507: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2025-55092MEDIUMPotential out of bound read in _nx_ipv4_option_process()EPSS 0.3%CVE-2025-24149MEDIUMAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS SeqEPSS 0.3%CVE-2026-37535HIGHopenxc/isotp-c thru commit 5a5d19245f65189202719321facd49ce6f5d46ac (2021-08-09) contains an out-of-bounds read in the ISO-TP Single Frame rEPSS 0.3%CVE-2026-45615HIGHmouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OER PayloadEPSS 0.3%CVE-2025-52512HIGHAn issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in out-of-bounds memEPSS 0.3%CVE-2020-35535—In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when proEPSS 0.3%CVE-2026-3894CRITICALOut-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.EPSS 0.3%CVE-2026-64685MEDIUMImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file checkEPSS 0.3%CVE-2026-4459HIGHOut of bounds read and write in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corrEPSS 0.3%CVE-2026-4440HIGHOut of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write viaEPSS 0.3%CVE-2022-28183HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can caEPSS 0.3%CVE-2026-4462HIGHOut of bounds read in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform an out of bounds memory read via aEPSS 0.3%CVE-2026-45358MEDIUMImageMagick: Out-of-Bounds Read of a single byte in meta encoderEPSS 0.3%CVE-2026-17423HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2026-84968MEDIUMHeap out-of-bounds read via corrupt nested BSON in field path error messageEPSS 0.3%CVE-2026-17701CRITICALInsufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromEPSS 0.3%