Fallos del tipo CWE-125
5176 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-10658HIGHOut-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validationEPSS 0.3%CVE-2025-71264LOWMumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).EPSS 0.3%CVE-2024-53834HIGHIn sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect bounds check. This couldEPSS 0.3%CVE-2024-9750HIGHTungsten Automation Power PDF PNG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-8814HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-13820MEDIUMOut of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer processEPSS 0.3%CVE-2024-9751HIGHTungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-68132LOWEVerest has out-of-bounds read in DZG_GSH01 SLIP CRC parser that can crash powermeter driverEPSS 0.3%CVE-2024-9755HIGHTungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-8812HIGHPDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-8833HIGHPDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-28571MEDIUMBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the fEPSS 0.3%CVE-2026-73462HIGHOn affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IEPSS 0.3%CVE-2026-5886MEDIUMOut of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive infoEPSS 0.3%CVE-2026-73761MEDIUMUnauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclosure in AOS-CXEPSS 0.3%CVE-2022-49368HIGHnet: ethernet: mtk_eth_soc: out of bounds read in mtk_hwlro_get_fdir_entry()EPSS 0.3%CVE-2018-9484HIGHIn l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remotEPSS 0.3%CVE-2024-4079HIGHOut of Bounds Read Due to Missing Bounds Check in LabVIEWEPSS 0.3%CVE-2026-17028MEDIUMPower System Out-of-bounds ReadEPSS 0.3%CVE-2020-36602MEDIUMThere is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and EPSS 0.3%