Fallos del tipo CWE-125
5159 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2024-41125HIGHOut-of-bounds read in SNMP when decoding a string in Contiki-NGEPSS 0.3%CVE-2026-9122MEDIUMOut of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive informatEPSS 0.3%CVE-2026-13873MEDIUMOut of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fEPSS 0.3%CVE-2026-28692MEDIUMImageMagick has a heap buffer over-read via 32-bit integer overflow in MAT decoderEPSS 0.3%CVE-2023-38213MEDIUMZDI-CAN-21094: Adobe Dimension GLB File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-46955MEDIUMAn issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed EPSS 0.3%CVE-2026-41677LOWrust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized lengthEPSS 0.3%CVE-2022-31617HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabiEPSS 0.3%CVE-2022-4144MEDIUMAn out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of thEPSS 0.3%CVE-2025-21124MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-41126HIGHOut-of-bounds read when decoding SNMP messages in Contiki-NGEPSS 0.3%CVE-2026-9996MEDIUMOut of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive inforEPSS 0.3%CVE-2026-27289HIGHPhotoshop Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-13858MEDIUMOut of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information fEPSS 0.3%CVE-2024-49510MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-27269HIGHPremiere Pro | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-27287HIGHInCopy | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-49512MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-27294HIGHAdobe Framemaker | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-24826CRITICALOut-of-bounds write in turso3dEPSS 0.3%