Fallos del tipo CWE-125
5180 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-19028MEDIUMHDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds readEPSS 0.2%CVE-2025-20688MEDIUMIn wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure EPSS 0.2%CVE-2026-54633MEDIUMPoDoFo: Heap Out-of-Bounds Read in Indexed Color Space Image Decoding (FetchScanLine)EPSS 0.2%CVE-2026-65979MEDIUMOpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN)EPSS 0.2%CVE-2026-53566MEDIUMOut-of-bounds memory readEPSS 0.2%CVE-2025-55307LOWAn issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. Opening a malicious PDF containing a craftedEPSS 0.2%CVE-2025-64893HIGHDNG SDK | Out-of-bounds Read (CWE-125)EPSS 0.2%CVE-2026-90557MEDIUMFreeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via SavegameEPSS 0.2%CVE-2025-5046HIGHDGN File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.2%CVE-2026-2241MEDIUMjanet-lang janet os.c os_strftime out-of-boundsEPSS 0.2%CVE-2026-0155MEDIUMIn ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information discEPSS 0.2%CVE-2024-32667LOWOut-of-bounds read for some OpenCL(TM) software may allow an authenticated user to potentially enable denial of service via local access.EPSS 0.2%CVE-2025-6034HIGHOut of Bounds Read in DefaultFontOptions() in NI Circuit Design SuiteEPSS 0.2%CVE-2025-10101HIGHAvast antivirus heap buffer OOB read when scanning a malformed Mach-O fileEPSS 0.2%CVE-2026-28419MEDIUMVim has Heap-based Buffer Underflow in Emacs tags parsingEPSS 0.2%CVE-2025-14421LOWpdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.2%CVE-2023-30760LOWOut-of-bounds read in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticatedEPSS 0.2%CVE-2023-25494MEDIUM
A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attackeEPSS 0.2%CVE-2023-21430MEDIUMAn out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 ReleaseEPSS 0.2%CVE-2024-32893HIGHIn _s5e9865_mif_set_rate of exynos_dvfs.c, there is a possible out of bounds read due to improper casting. This could lead to local informatEPSS 0.2%