Fallos del tipo CWE-125
5178 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-11096MEDIUMOut of bounds read in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information fEPSS 0.2%CVE-2026-21303MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-1508—An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some speciEPSS 0.2%CVE-2025-21600HIGHJunos OS and Junos OS Evolved: With certain BGP options enabled, receipt of specifically malformed BGP update causes RPD crashEPSS 0.2%CVE-2023-27915HIGHA maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violEPSS 0.2%CVE-2024-53082HIGHvirtio_net: Add hash_key_length checkEPSS 0.2%CVE-2026-12461MEDIUMOut of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive iEPSS 0.2%CVE-2026-87586MEDIUMOut of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a craftEPSS 0.2%CVE-2026-12478MEDIUMLibsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)EPSS 0.2%CVE-2026-75032MEDIUMBluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folderEPSS 0.2%CVE-2022-49218HIGHdrm/dp: Fix OOB read when handling Post Cursor2 registerEPSS 0.2%CVE-2026-87596MEDIUMOut of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a craftEPSS 0.2%CVE-2026-20420MEDIUMIn Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connectEPSS 0.2%CVE-2026-9113MEDIUMOut of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read EPSS 0.2%CVE-2026-73324MEDIUMVLC media player 3.0.0 through 3.0.23 information disclosure vulnerabilityEPSS 0.2%CVE-2024-27528HIGHwasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution.EPSS 0.2%CVE-2022-39157HIGHA vulnerability has been identified in Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.0 (All versions >= V34.0.252 < V34.0.254), EPSS 0.2%CVE-2021-33105MEDIUMOut-of-bounds read in some Intel(R) Core(TM) processors with Radeon(TM) RX Vega M GL integrated graphics before version 21.10 may allow an aEPSS 0.2%CVE-2025-54237MEDIUMSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2021-25483MEDIUMLack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.EPSS 0.2%