Fallos del tipo CWE-125
5176 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2025-61952MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker coEPSS 0.3%CVE-2025-12725HIGHOut of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memorEPSS 0.3%CVE-2025-47873MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker coEPSS 0.3%CVE-2025-66042MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker coEPSS 0.3%CVE-2025-64735MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker coEPSS 0.3%CVE-2024-47420MEDIUMAnimate | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-47446MEDIUMAfter Effects | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-47419MEDIUMAnimate | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-30298MEDIUMAdobe Animate SWF File Parsing Memory corruptionEPSS 0.3%CVE-2024-41872MEDIUMMedia Encoder | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2025-65119MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker coEPSS 0.3%CVE-2024-41873MEDIUMMedia Encoder | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-0136HIGHIn Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additionEPSS 0.3%CVE-2024-47445MEDIUMAfter Effects | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-41870MEDIUMMedia Encoder | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-45147MEDIUMBridge | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2025-62500MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker coEPSS 0.3%CVE-2025-61979MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker coEPSS 0.3%CVE-2024-41867MEDIUMAfter Effects | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-22882MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker coEPSS 0.3%