Fallos del tipo CWE-125
5176 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2024-25392MEDIUMAn out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.EPSS 0.3%CVE-2022-49623HIGHpowerpc/xive/spapr: correct bitmap allocation sizeEPSS 0.3%CVE-2026-11077HIGHBad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted EPSS 0.3%CVE-2024-32635HIGHA vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), TeamceEPSS 0.3%CVE-2022-43043MEDIUMGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTimeOffset at /bifs/fielEPSS 0.3%CVE-2026-50491HIGHCode Integrity DLL (ci.dll) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-32055HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past EPSS 0.3%CVE-2025-26441MEDIUMIn add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informationEPSS 0.3%CVE-2025-11840MEDIUMGNU Binutils ldmisc.c vfinfo out-of-boundsEPSS 0.3%CVE-2026-54592HIGHOj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested InputEPSS 0.3%CVE-2026-44064HIGHASP session ID out-of-bounds accessEPSS 0.3%CVE-2026-9913MEDIUMInappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform out of boundEPSS 0.3%CVE-2025-2231HIGHPDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-75369HIGHAn out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit EPSS 0.3%CVE-2023-53333HIGHnetfilter: conntrack: dccp: copy entire header to stack buffer, not just basic oneEPSS 0.3%CVE-2024-52998MEDIUMSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2022-20604MEDIUMIn SAECOMM_SetDcnIdForPlmn of SAECOMM_DbManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead EPSS 0.3%CVE-2025-3160MEDIUMOpen Asset Import Library Assimp File SceneCombiner.cpp AddNodeHashes out-of-boundsEPSS 0.3%CVE-2025-10883HIGHCATPRODUCT File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.3%CVE-2025-5200MEDIUMOpen Asset Import Library Assimp MDLLoader.cpp InternReadFile_Quake1 out-of-boundsEPSS 0.3%