Fallos del tipo CWE-125
5180 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2023-22808LOWAn issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. TEPSS 0.2%CVE-2025-6632MEDIUMPSD File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2025-62525HIGHOpenWrt vulnerable to local privilage escalationEPSS 0.2%CVE-2024-6876MEDIUMOut-of-bounds read in OSCAT-LibraryEPSS 0.2%CVE-2026-33317HIGHOP-TEE: PKCS#11 TA out-of-bounds read and memory disclosureEPSS 0.2%CVE-2025-32776MEDIUMOpenRazer Vulnerable to Out of Bounds ReadEPSS 0.2%CVE-2025-23050LOWQLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero).EPSS 0.2%CVE-2026-64202HIGHOut-of-Bounds Read Vulnerability in NI LabVIEW when loading VIEPSS 0.2%CVE-2025-47135MEDIUMDimension | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-57077HIGHYAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_lenEPSS 0.2%CVE-2024-38658HIGHThere is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens EPSS 0.2%CVE-2026-64201HIGHOut-of-Bounds Read Vulnerability in NI LabVIEW when loading VIEPSS 0.2%CVE-2026-32864HIGHOut-of-Bounds Read in mgcore_SH_25_3!aligned_free()EPSS 0.2%CVE-2024-9508HIGHHorner Automation Cscape Out-of-bounds ReadEPSS 0.2%CVE-2026-32863HIGHOut-of-Bounds Read in sentry_transaction_context_set_operation()EPSS 0.2%CVE-2026-64203HIGHOut-of-Bounds Read Vulnerability in NI LabVIEW when loading VIEPSS 0.2%CVE-2026-3664MEDIUMxlnt-community xlnt Encrypted XLSX File compound_document.cpp read_directory out-of-boundsEPSS 0.2%CVE-2022-20541MEDIUMIn phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local inforEPSS 0.2%CVE-2024-38389HIGHThere is an Out-of-bounds read vulnerability in TELLUS (v4.0.19.0 and earlier) and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a spEPSS 0.2%CVE-2025-64736MEDIUMAn out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (5462afbEPSS 0.2%