Fallos del tipo CWE-125
5180 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2026-47519HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds rEPSS 0.1%CVE-2026-47535HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A suEPSS 0.1%CVE-2026-47521HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds rEPSS 0.1%CVE-2026-47499HIGHNVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a guest could cause an out-of-EPSS 0.1%CVE-2026-47592HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an EPSS 0.1%CVE-2026-47520HIGHNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds rEPSS 0.1%CVE-2026-47166MEDIUMImageMagick: Heap Buffer Over-Read in distributed pixel cache serverEPSS 0.1%CVE-2026-73067MEDIUMTesseract: Heap OOB read in the DAWG loaderEPSS 0.1%CVE-2026-81646MEDIUMOut-of-bounds read vulnerability in the graphics module.
Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2025-62862MEDIUMAmpere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorreEPSS 0.1%CVE-2026-33968LOWAn issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driveEPSS 0.1%CVE-2022-20608MEDIUMIn Pixel cellular firmware, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information diEPSS 0.1%CVE-2022-20527MEDIUMIn HalCoreCallback of halcore.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local informationEPSS 0.1%CVE-2022-20609MEDIUMIn Pixel cellular firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclEPSS 0.1%CVE-2025-11775MEDIUMAn out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crEPSS 0.1%CVE-2026-46690MEDIUMunbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX raceEPSS 0.1%CVE-2024-20022MEDIUMIn lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with SystEPSS 0.1%CVE-2025-32007MEDIUMOut-of-bounds read for some TDX before version tdx module 1.5.24 within Ring 0: Hypervisor may allow an information disclosure. Authorized aEPSS 0.1%CVE-2024-25988HIGHIn SAEMM_DiscloseGuti of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead toEPSS 0.1%CVE-2022-20528LOWIn findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%