Fallos del tipo CWE-125
5126 resultadosLeitura fora dos limites do buffer
Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.
Ejemplo
Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.
Cómo mitigar
Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).
CVE-2021-44431—A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected prEPSS 0.5%CVE-2025-53379HIGHA out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remotEPSS 0.5%CVE-2026-69244HIGHAIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)EPSS 0.5%CVE-2023-52727HIGHOpen Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.EPSS 0.5%CVE-2020-8872MEDIUMThis vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.1-47117. An EPSS 0.5%CVE-2025-67721MEDIUMAircompressor's Snappy and LZ4 Java-based decompressor implementation can leak information from reused output bufferEPSS 0.5%CVE-2023-6606HIGHKernel: out-of-bounds read vulnerability in smbcalcsizeEPSS 0.5%CVE-2026-55122HIGHMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-51606HIGHKofax Power PDF U3D File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-32188HIGHMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-34000MEDIUMXwayland: xorg: x.org x server: information disclosure and denial of service via out-of-bounds read in xkb geometry processing.EPSS 0.5%CVE-2025-27931MEDIUMAn out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EPSS 0.5%CVE-2024-34244HIGHlibmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed EPSS 0.5%CVE-2026-62959HIGHCoturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)EPSS 0.5%CVE-2025-62202HIGHMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-63383HIGHLibevent: decode_tag_internal() can lead to out-of-bounds readEPSS 0.5%CVE-2025-62468MEDIUMWindows Defender Firewall Service Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-58528MEDIUMWindows USB Audio Class Driver Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-78455MEDIUMXbox Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-86227LOWvalkey-io valkey kvstore.c kvstoreGetHashtable out-of-boundsEPSS 0.5%