Fallos del tipo CWE-125
5179 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2025-30420HIGHOut of Bounds Read in Bitmap::InternalDraw() in NI Circuit Design SuiteEPSS 0.2%CVE-2023-39986HIGHOut-of-bounds Read Vulnerability in Hitachi EH-VIEW (Designer)EPSS 0.2%CVE-2026-91958MEDIUMFreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor IndexEPSS 0.2%CVE-2025-9136MEDIUMlibretro RetroArch file_stream.c filestream_vscanf out-of-boundsEPSS 0.2%CVE-2022-40136MEDIUMAn information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker wiEPSS 0.2%CVE-2026-57432HIGHPerl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpackEPSS 0.2%CVE-2025-54201MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54197MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-40135MEDIUMAn information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and EPSS 0.2%CVE-2025-54186MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54204MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2022-40134MEDIUMAn information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access andEPSS 0.2%CVE-2025-54200MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54188MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54205MEDIUMSubstance3D - Sampler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54194MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54189MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-54199MEDIUMSubstance3D - Modeler | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2025-43361HIGHAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7.2, macOS EPSS 0.2%CVE-2025-54191MEDIUMSubstance3D - Painter | Out-of-bounds Read (CWE-125)EPSS 0.2%