Fallos del tipo CWE-125
5176 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-69617HIGHWindows Resilient File System (ReFS) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69630HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-78475MEDIUMGimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loaderEPSS 0.3%CVE-2026-82330MEDIUMGimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds checkEPSS 0.3%CVE-2026-8541MEDIUMOut of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtaEPSS 0.3%CVE-2026-8543MEDIUMOut of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage inEPSS 0.3%CVE-2026-33450LOWOut of bounds read in Secure Access MacOS clients prior to 14.50EPSS 0.3%CVE-2026-82328MEDIUMGimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette countEPSS 0.3%CVE-2024-27529HIGHwasm3 139076a contains memory leaks in Read_utf8.EPSS 0.3%CVE-2026-13975MEDIUMOut of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2026-13890MEDIUMOut of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process EPSS 0.3%CVE-2026-72952HIGHWindows Spaceport.sys Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-8546MEDIUMOut of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2026-20611HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 andEPSS 0.3%CVE-2026-31885MEDIUMFreeRDP has an out-of-bounds read in ADPCM decoders due to missing predictor/step_index bounds checksEPSS 0.3%CVE-2026-13480LOWOut-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handlerEPSS 0.3%CVE-2025-63523MEDIUMFeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticatEPSS 0.3%CVE-2024-50268HIGHusb: typec: fix potential out of bounds in ucsi_ccg_update_set_new_cam_cmd()EPSS 0.3%CVE-2024-45463HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.3%CVE-2024-30281MEDIUMSubstance3D - Designer | Out-of-bounds Read (CWE-125)EPSS 0.3%