Fallos del tipo CWE-125
5179 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2025-21905HIGHwifi: iwlwifi: limit printed string from FW fileEPSS 0.2%CVE-2026-13479LOWOut-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handlerEPSS 0.2%CVE-2024-52574HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2024-33490HIGHA vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read EPSS 0.2%CVE-2026-88369HIGHzserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().EPSS 0.2%CVE-2024-33491HIGHA vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read EPSS 0.2%CVE-2023-30084MEDIUMAn issue found in libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the stackVal function in util/decompile.EPSS 0.2%CVE-2024-33492HIGHA vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected applications contain an out of bounds read EPSS 0.2%CVE-2024-26608HIGHksmbd: fix global oob in ksmbd_nl_policyEPSS 0.2%CVE-2022-45484LOWA vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), TeamcenEPSS 0.2%CVE-2021-25493MEDIUMLack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB readEPSS 0.2%CVE-2022-32936MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13. An app may be able to disclose EPSS 0.2%CVE-2025-43226MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS SeEPSS 0.2%CVE-2026-43628HIGHllama.cpp b3978–b9058 Integer Underflow via DRY SamplerEPSS 0.2%CVE-2024-32607MEDIUMHDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.EPSS 0.2%CVE-2026-80101MEDIUMGimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validationEPSS 0.2%CVE-2025-21794HIGHHID: hid-thrustmaster: fix stack-out-of-bounds read in usb_check_int_endpoints()EPSS 0.2%CVE-2026-92176HIGHpdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.2%CVE-2024-27860MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An application may be able to read restricteEPSS 0.2%CVE-2026-36613MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POSEPSS 0.2%