CWE-126— Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.— MITRE CWE catalog
544 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-126page 1 of 11
- CVE-2017-17772CRITICALCVSS 9.8EG 9.82024-11-26
In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.
- CVE-2023-36397CRITICALCVSS 9.8EG 9.82023-11-14
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- CVE-2019-3563CRITICALCVSS 9.8EG 9.82019-04-29
Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00
- CVE-2018-14790CRITICALCVSS 9.8EG 9.82018-10-01
Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on the device.
- CVE-2017-7679CRITICALCVSS 9.8EG 9.82017-06-20
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
- CVE-2022-1927CRITICALCVSS 7.8EG 9.82022-05-29
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- CVE-2024-38373CRITICALCVSS 9.6EG 9.62024-06-24
FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS r…
- CVE-2025-12106CRITICALCVSS 9.1EG 9.12025-12-01
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
- CVE-2025-55081CRITICALCVSS 9.1EG 9.12025-10-15
In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hello message: the ciphersuite length and compression method l…
- CVE-2023-51773CRITICALCVSS 9.1EG 9.12024-02-29
BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.
- CVE-2021-34584CRITICALCVSS 9.1EG 9.12021-10-26
Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.
- CVE-2019-11036CRITICALCVSS 9.1EG 9.12019-05-03
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosur…
- CVE-2023-49285CRITICALCVSS 7.5EG 9.02023-12-04
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users…
- CVE-2026-66312HIGHCVSS 8.8EG 8.82026-08-03
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
- CVE-2025-36855HIGHCVSS 8.8EG 8.82025-09-08
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product rea…
- CVE-2025-21176HIGHCVSS 8.8EG 8.82025-01-14
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- CVE-2024-38265HIGHCVSS 8.8EG 8.82024-10-08
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2022-2175HIGHCVSS 7.8EG 8.82022-06-23
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- CVE-2023-28572HIGHCVSS 6.6EG 8.82023-11-07
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
- CVE-2022-20823HIGHCVSS 8.6EG 8.62022-08-25
A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete inpu…
- CVE-2022-20714HIGHCVSS 8.6EG 8.62022-04-15
A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to …
- CVE-2021-1588HIGHCVSS 8.6EG 8.62021-08-25
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerabi…
- CVE-2021-1373HIGHCVSS 8.6EG 8.62021-03-24
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, rem…
- CVE-2020-3399HIGHCVSS 8.6EG 8.62020-09-24
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a …
- CVE-2025-32704HIGHCVSS 8.4EG 8.42025-05-13
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2024-33056HIGHCVSS 8.4EG 8.42024-12-02
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
- CVE-2018-5852HIGHCVSS 8.4EG 8.42024-11-26
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'
- CVE-2024-33047HIGHCVSS 8.4EG 8.42024-09-02
Memory corruption when the captureRead QDCM command is invoked from user-space.
- CVE-2026-58013HIGHCVSS 8.2EG 8.22026-06-30
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This v…
- CVE-2026-58012HIGHCVSS 8.2EG 8.22026-06-30
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using …
- CVE-2026-58010HIGHCVSS 8.2EG 8.22026-06-30
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bound…
- CVE-2026-5260HIGHCVSS 8.2EG 8.22026-05-26
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption…
- CVE-2026-24028HIGHCVSS 8.2EG 8.22026-03-31
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of s…
- CVE-2025-21488HIGHCVSS 8.2EG 8.22025-09-24
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
- CVE-2025-21487HIGHCVSS 8.2EG 8.22025-09-24
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
- CVE-2025-21484HIGHCVSS 8.2EG 8.22025-09-24
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
- CVE-2025-21427HIGHCVSS 8.2EG 8.22025-07-08
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
- CVE-2024-53026HIGHCVSS 8.2EG 8.22025-06-03
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
- CVE-2024-53021HIGHCVSS 8.2EG 8.22025-06-03
Information disclosure may occur while processing goodbye RTCP packet from network.
- CVE-2024-53020HIGHCVSS 8.2EG 8.22025-06-03
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
- CVE-2024-53019HIGHCVSS 8.2EG 8.22025-06-03
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
- CVE-2024-49846HIGHCVSS 8.2EG 8.22025-05-06
Memory corruption while decoding of OTA messages from T3448 IE.
- CVE-2024-45552HIGHCVSS 8.2EG 8.22025-04-07
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
- CVE-2024-49839HIGHCVSS 8.2EG 8.22025-02-03
Memory corruption during management frame processing due to mismatch in T2LM info element.
- CVE-2024-49838HIGHCVSS 8.2EG 8.22025-02-03
Information disclosure while parsing the OCI IE with invalid length.
- CVE-2024-33073HIGHCVSS 8.2EG 8.22024-10-07
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
- CVE-2024-33064HIGHCVSS 8.2EG 8.22024-10-07
Information disclosure while parsing the multiple MBSSID IEs from the beacon.
- CVE-2024-23359HIGHCVSS 8.2EG 8.22024-09-02
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
- CVE-2023-43555HIGHCVSS 8.2EG 8.22024-06-03
Information disclosure in Video while parsing mp2 clip with invalid section length.
- CVE-2023-33058HIGHCVSS 8.2EG 8.22024-02-06
Information disclosure in Modem while processing SIB5.
Map vulnerabilities like CWE-126 to your infrastructure
EchelonGraph correlates every CVE — across CWE-126 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →