Fallos del tipo CWE-125
5159 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2022-43282HIGHwasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.EPSS 0.3%CVE-2022-43280HIGHwasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.EPSS 0.3%CVE-2024-35423HIGHvmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.EPSS 0.3%CVE-2026-5292HIGHOut of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read vEPSS 0.3%CVE-2025-7698MEDIUMOut-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic PlEPSS 0.3%CVE-2024-20127HIGHIn Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no addiEPSS 0.3%CVE-2024-20129HIGHIn Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no addiEPSS 0.3%CVE-2025-0437MEDIUMOut of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.3%CVE-2024-20128HIGHIn Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no addiEPSS 0.3%CVE-2026-12298MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2026-44518MEDIUMliboqs: XMSS Buffer Overread BugEPSS 0.3%CVE-2026-24812CRITICALAn improper pointer arithmetic in root-project/root at builtins/zlib/inftrees.cEPSS 0.3%CVE-2026-66759HIGHGimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns imagesEPSS 0.3%CVE-2023-4721MEDIUMOut-of-bounds Read in gpac/gpacEPSS 0.3%CVE-2024-22957MEDIUMswftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the function dict_do_lookup in swftools/lib/q.c:1190.EPSS 0.3%CVE-2022-42901HIGHBentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when opening crafted XMTEPSS 0.3%CVE-2026-46344MEDIUMliboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter mismatch (xmss_commons.c:194)EPSS 0.3%CVE-2025-53051LOWVulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. EasilyEPSS 0.3%CVE-2026-56362LOWImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata DesynchronizationEPSS 0.3%CVE-2026-9889HIGHOut of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a EPSS 0.3%