Fallos del tipo CWE-125
5177 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2023-27854HIGHRockwell Automation Arena® Simulation Out of Bounds Read VulnerabilityEPSS 0.3%CVE-2021-47636HIGHubifs: Fix read out-of-bounds in ubifs_wbuf_write_nolock()EPSS 0.3%CVE-2023-27946HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, EPSS 0.3%CVE-2026-12310HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2023-32288HIGHOut-of-bounds read vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted SIM file may lead to infoEPSS 0.3%CVE-2024-9759LOWTungsten Automation Power PDF GIF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-9762LOWTungsten Automation Power PDF OXPS File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-22338MEDIUMOut-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable informatEPSS 0.3%CVE-2024-9757LOWTungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-9760LOWTungsten Automation Power PDF PNG File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-9754LOWTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-9763LOWTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-9753LOWTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-9761LOWTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-9749LOWTungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-12314HIGHMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2024-9752LOWTungsten Automation Power PDF JPG File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.3%CVE-2023-32542HIGHOut-of-bounds read vulnerability exists in TELLUS v4.0.15.0 and TELLUS Lite v4.0.15.0. Opening a specially crafted V8 file may lead to inforEPSS 0.3%CVE-2024-22705HIGHAn issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strnEPSS 0.3%CVE-2026-25209MEDIUMOut-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc5EPSS 0.3%