Fallos del tipo CWE-125
5179 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2025-9327LOWFoxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-9325LOWFoxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-9323LOWFoxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-43346MEDIUMAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOEPSS 0.2%CVE-2026-5392LOWwolfSSL heap OOB read in PKCS7 SignedData streamingEPSS 0.2%CVE-2024-26588HIGHLoongArch: BPF: Prevent out-of-bounds memory accessEPSS 0.2%CVE-2023-39187HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-39182HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2026-12026MEDIUMOut of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2026-20421MEDIUMIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connecEPSS 0.2%CVE-2026-28526LOWBlueKitchen BTstack < 1.8.1 AVRCP Controller LIST_PLAYER_APPLICATION_SETTING_* Handlers OOB ReadEPSS 0.2%CVE-2023-39183HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-39186HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-27912HIGHA maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can force an Out-of-Bound Read. A malicious actor can leverage thEPSS 0.2%CVE-2023-39184HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2023-39185HIGHA vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of boundEPSS 0.2%CVE-2026-25920MEDIUMSumatraPDF has a heap out-of-bounds read in MOBI HuffDic decompressorEPSS 0.2%CVE-2023-3487HIGHInteger overflow in Silicon Labs Gecko Bootloader leads to unbounded memory accessEPSS 0.2%CVE-2023-32403—This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.EPSS 0.2%CVE-2024-33493HIGHA vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read EPSS 0.2%