CWE-126— Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.— MITRE CWE catalog
544 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-126page 10 of 11
- CVE-2022-42779MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2022-42774MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2022-42762MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2022-42759MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2022-39132MEDIUMCVSS 5.5EG 5.52022-12-06
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-39130MEDIUMCVSS 5.5EG 5.52022-12-06
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-38673MEDIUMCVSS 5.5EG 5.52022-10-14
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-38671MEDIUMCVSS 5.5EG 5.52022-10-14
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
- CVE-2022-2301MEDIUMCVSS 5.5EG 5.52022-07-04
Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.
- CVE-2021-34325MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affected applications lacks proper validation of user-supplied data when parsing JT files. This …
- CVE-2021-34322MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The JPEG2K_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing J2K fil…
- CVE-2021-34321MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The VisDraw.dll library in affected applications lacks proper validation of user-supplied data when parsing J2K files. Th…
- CVE-2021-34320MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affected applications lacks proper validation of user-supplied data when parsing JT files. This …
- CVE-2021-34308MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files.…
- CVE-2021-34307MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF file…
- CVE-2021-34304MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF file…
- CVE-2021-34303MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF file…
- CVE-2021-34302MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files.…
- CVE-2021-34299MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF file…
- CVE-2026-62353MEDIUMCVSS 5.4EG 5.42026-07-15
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte…
- CVE-2025-11617MEDIUMCVSS 5.4EG 5.42025-10-10
A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using I…
- CVE-2025-11616MEDIUMCVSS 5.4EG 5.42025-10-10
A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect ap…
- CVE-2025-29956MEDIUMCVSS 5.4EG 5.42025-05-13
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
- CVE-2026-20541MEDIUMCVSS 5.3EG 5.32026-10-05
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privile…
- CVE-2026-20540MEDIUMCVSS 5.3EG 5.32026-10-05
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges …
- CVE-2026-20539MEDIUMCVSS 5.3EG 5.32026-10-05
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges …
- CVE-2026-20538MEDIUMCVSS 5.3EG 5.32026-10-05
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privile…
- CVE-2026-76653MEDIUMCVSS 5.3EG 5.32026-09-10
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and mod…
- CVE-2026-65936MEDIUMCVSS 5.3EG 5.32026-08-13
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
- CVE-2026-65933MEDIUMCVSS 5.3EG 5.32026-08-13
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
- CVE-2026-55238MEDIUMCVSS 5.3EG 5.32026-07-20
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validatio…
- CVE-2026-49854MEDIUMCVSS 5.3EG 5.32026-06-12
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the …
- CVE-2026-45684MEDIUMCVSS 5.3EG 5.32026-05-18
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using …
- CVE-2026-8463MEDIUMCVSS 5.3EG 5.32026-05-13
Crypt::Argon2 versions from 0.017 before 0.031 for Perl perform a heap out-of-bounds read in argon2_verify on empty encoded input. The auto-detect form of argon2_verify passes encoded_len - 1 as the length argument to memchr without check…
- CVE-2026-41898MEDIUMCVSS 5.3EG 5.32026-04-24
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_state…
- CVE-2026-5772MEDIUMCVSS 5.3EG 5.32026-04-09
A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard * exhausts the entire hostname string, the …
- CVE-2026-26271MEDIUMCVSS 5.3EG 5.32026-02-25
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data…
- CVE-2025-12745MEDIUMCVSS 5.3EG 5.32025-11-05
A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is restricted to local e…
- CVE-2025-60729MEDIUMCVSS 5.3EG 5.32025-10-24
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
- CVE-2025-55093MEDIUMCVSS 5.3EG 5.32025-10-17
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corruption of 4 bytes o…
- CVE-2025-55092MEDIUMCVSS 5.3EG 5.32025-10-17
In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with the timestamp option.
- CVE-2025-55084MEDIUMCVSS 5.3EG 5.32025-10-16
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field.
- CVE-2025-55083MEDIUMCVSS 5.3EG 5.32025-10-15
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read.
- CVE-2023-45919MEDIUMCVSS 5.3EG 5.32024-03-27
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
- CVE-2023-6936MEDIUMCVSS 5.3EG 5.32024-02-20
In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for de…
- CVE-2023-38152MEDIUMCVSS 5.3EG 5.32023-09-12
DHCP Server Service Information Disclosure Vulnerability
- CVE-2023-36801MEDIUMCVSS 5.3EG 5.32023-09-12
DHCP Server Service Information Disclosure Vulnerability
- CVE-2023-3649MEDIUMCVSS 5.3EG 5.32023-07-14
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
- CVE-2023-21720MEDIUMCVSS 5.3EG 5.32023-02-14
Microsoft Edge (Chromium-based) Tampering Vulnerability
- CVE-2021-22552MEDIUMCVSS 5.3EG 5.32021-08-02
An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory …
Map vulnerabilities like CWE-126 to your infrastructure
EchelonGraph correlates every CVE — across CWE-126 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →