Fallos del tipo CWE-125
5179 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2023-38526HIGHA vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35EPSS 0.2%CVE-2025-7992HIGHAshlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.2%CVE-2022-3737HIGHOut-of-bounds Read in PHOENIX CONTACT Automationworx Software SuiteEPSS 0.2%CVE-2025-43386HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 andEPSS 0.2%CVE-2023-22321LOWDatakit CrossCAD/WareEPSS 0.2%CVE-2026-2659MEDIUMSquirrel sqfuncstate.cpp PopTarget out-of-boundsEPSS 0.2%CVE-2023-22846LOWDatakit CrossCAD/WareEPSS 0.2%CVE-2023-22354LOWDatakit CrossCAD/WareEPSS 0.2%CVE-2023-38527HIGHA vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Teamcenter ViEPSS 0.2%CVE-2025-7233LOWIrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2026-11301HIGHInappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of EPSS 0.2%CVE-2025-66497MEDIUMFoxit PDF Reader 3D Annotation Out-of-Bounds Memory Access VulnerabilityEPSS 0.2%CVE-2025-7324HIGHIrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.2%CVE-2025-66498MEDIUMFoxit PDF Reader 3D Annotation Out-of-Bounds Memory Access VulnerabilityEPSS 0.2%CVE-2025-66496MEDIUMFoxit PDF Reader 3D Annotation Out-of-Bounds Memory Access VulnerabilityEPSS 0.2%CVE-2025-7319HIGHIrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-1764MEDIUMLocalsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leads to denial of service or information disclosure when parsing mp3 filesEPSS 0.2%CVE-2026-80490—Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringifiedEPSS 0.2%CVE-2026-25585HIGHiccDEV vulnerable to OOB in CIccXform3DLut::Apply()EPSS 0.2%CVE-2025-65396MEDIUMA vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hiEPSS 0.2%