Fallos del tipo CWE-125
5177 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-27216MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-34616MEDIUMDNG SDK | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-44281MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS VeEPSS 0.3%CVE-2026-27219MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-27270MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-27268MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2026-15534MEDIUMPerl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatchEPSS 0.3%CVE-2025-5165MEDIUMOpen Asset Import Library Assimp MDCLoader.cpp ValidateSurfaceHeader out-of-boundsEPSS 0.3%CVE-2025-43584MEDIUMSubstance3D - Viewer | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2024-53873LOWNVIDIA CUDA toolkit for Windows contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing EPSS 0.3%CVE-2025-9326HIGHFoxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2022-39156—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), EPSS 0.3%CVE-2025-5168MEDIUMOpen Asset Import Library Assimp MDLLoader.cpp ImportUVCoordinate_3DGS_MDL345 out-of-boundsEPSS 0.3%CVE-2022-39153—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), EPSS 0.3%CVE-2023-41051LOWDefault functions in VolatileMemory trait lack bounds checks in vm-memoryEPSS 0.3%CVE-2025-32003MEDIUMOut-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, cpk 1.3.7 within RingEPSS 0.3%CVE-2025-5166MEDIUMOpen Asset Import Library Assimp MDC File Parser MDCLoader.cpp InternReadFile out-of-boundsEPSS 0.3%CVE-2022-39145—A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), EPSS 0.3%CVE-2025-5167MEDIUMOpen Asset Import Library Assimp LWOLoader.h GetS0 out-of-boundsEPSS 0.3%CVE-2025-5169MEDIUMOpen Asset Import Library Assimp MDLLoader.cpp InternReadFile_3DGS_MDL345 out-of-boundsEPSS 0.3%