Fallos del tipo CWE-125
5161 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2024-9720HIGHTrimble SketchUp Viewer SKP File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-20711MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VIIEPSS 0.3%CVE-2022-26369MEDIUMOut-of-bounds read in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentialEPSS 0.3%CVE-2025-4098HIGHOut-of-bounds Read in Horner Automation CscapeEPSS 0.3%CVE-2024-20771MEDIUMBridge 2024 MOV File parsing memory corruptionEPSS 0.3%CVE-2024-20710MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability IEPSS 0.3%CVE-2024-20714MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VEPSS 0.3%CVE-2024-20715MEDIUMAdobe Substance 3D Stager v2.1.1 Vulnerability VIIIEPSS 0.3%CVE-2022-46440MEDIUMttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.EPSS 0.3%CVE-2024-49529MEDIUMInDesign Desktop | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-20796MEDIUMAdobe Animation SWF File Parsing Memory CorruptionEPSS 0.3%CVE-2026-10999MEDIUMInteger overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer procEPSS 0.3%CVE-2026-18716HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2026-10927HIGHOut of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potEPSS 0.3%CVE-2024-20138HIGHIn wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure witEPSS 0.3%CVE-2026-10889HIGHOut of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to poEPSS 0.3%CVE-2023-34401LOWMercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which EPSS 0.3%CVE-2021-22484HIGHSome Huawei wearables have a vulnerability of not verifying the actual data size when reading data.
Successful exploitation of this vulnEPSS 0.3%CVE-2026-48040MEDIUMnetty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory AccessEPSS 0.3%CVE-2022-34677MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause EPSS 0.3%