Fallos del tipo CWE-125
5179 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-36613MEDIUMMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POSEPSS 0.2%CVE-2018-9349MEDIUMIn mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This could lead to denial of service with no aEPSS 0.2%CVE-2026-34776MEDIUMElectron: Out-of-bounds read in second-instance IPC on macOS and LinuxEPSS 0.2%CVE-2023-25008HIGHA malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result iEPSS 0.2%CVE-2025-1399LOWOut-of-bounds Read in libplctag libraryEPSS 0.2%CVE-2023-0621HIGHCVE-2023-0621EPSS 0.2%CVE-2025-1400LOWOut-of-bounds Read in libplctag libraryEPSS 0.2%CVE-2024-52613MEDIUMA heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) via a crafteEPSS 0.2%CVE-2026-101204MEDIUMFastStone Image Viewer TGA Image FSViewer.exe out-of-boundsEPSS 0.2%CVE-2025-1652HIGHMODEL File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2025-1433HIGHMODEL File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2026-101205MEDIUMFastStone Image Viewer PCX Decoder out-of-boundsEPSS 0.2%CVE-2025-1431HIGHSLDPRT File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2025-24448MEDIUMIllustrator | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-85052LOWOut of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2025-21789HIGHLoongArch: csum: Fix OoB access in IP checksum code for negative lengthsEPSS 0.2%CVE-2022-41613HIGHBentley Systems MicroStation Connect versions
10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when parsing DGN files, wEPSS 0.2%CVE-2026-79004LOWOut of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to reEPSS 0.2%CVE-2026-0956HIGHOut-Of-Bounds Read in Digilent DASYLabEPSS 0.2%CVE-2025-21920HIGHvlan: enforce underlying device typeEPSS 0.2%