CWE-126— Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.— MITRE CWE catalog
544 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-126page 11 of 11
- CVE-2021-1614MEDIUMCVSS 5.3EG 5.32021-07-22
A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory. This vulnerability is…
- CVE-2023-33078MEDIUMCVSS 5.1EG 5.12024-03-04
Information Disclosure while processing IOCTL request in FastRPC.
- CVE-2022-33220MEDIUMCVSS 5.1EG 5.12023-09-05
Information disclosure in Automotive multimedia due to buffer over-read.
- CVE-2026-18238MEDIUMCVSS 5.0EG 5.02026-09-05
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process m…
- CVE-2024-9843MEDIUMCVSS 5.0EG 5.02024-11-12
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
- CVE-2026-69474MEDIUMCVSS 4.8EG 4.82026-09-08
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.
- CVE-2026-40210MEDIUMCVSS 4.8EG 4.82026-06-25
An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash.
- CVE-2026-69316MEDIUMCVSS 4.7EG 4.72026-09-08
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
- CVE-2026-45460MEDIUMCVSS 4.7EG 4.72026-06-09
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2024-7347MEDIUMCVSS 4.7EG 4.72024-08-14
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX…
- CVE-2024-30071MEDIUMCVSS 4.7EG 4.72024-07-09
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- CVE-2024-30069MEDIUMCVSS 4.7EG 4.72024-06-11
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- CVE-2026-61350MEDIUMCVSS 4.6EG 4.62026-08-11
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
- CVE-2024-21340MEDIUMCVSS 4.6EG 4.62024-02-13
Windows Kernel Information Disclosure Vulnerability
- CVE-2021-22563MEDIUMCVSS 4.5EG 4.52021-11-01
Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector<T>> when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory. It is rec…
- CVE-2026-27799MEDIUMCVSS 4.4EG 4.42026-02-26
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occur…
- CVE-2023-43574MEDIUMCVSS 4.4EG 4.42023-11-08
A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
- CVE-2023-43572MEDIUMCVSS 4.4EG 4.42023-11-08
A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
- CVE-2023-43568MEDIUMCVSS 4.4EG 4.42023-11-08
A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
- CVE-2026-78516MEDIUMCVSS 4.3EG 4.32026-09-08
Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locally.
- CVE-2026-18024MEDIUMCVSS 4.3EG 4.32026-08-13
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance …
- CVE-2026-14678MEDIUMCVSS 4.3EG 4.32026-08-13
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL …
- CVE-2026-59840MEDIUMCVSS 4.3EG 4.32026-07-14
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7…
- CVE-2025-43892MEDIUMCVSS 4.3EG 4.32026-07-14
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a port…
- CVE-2026-6575MEDIUMCVSS 4.3EG 4.32026-05-14
Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that arra…
- CVE-2026-0930MEDIUMCVSS 4.3EG 4.32026-04-20
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacent stack memory t…
- CVE-2022-42768MEDIUMCVSS 4.3EG 4.32022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2024-57970MEDIUMCVSS 4.0EG 4.02025-02-16
libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname.
- CVE-2026-97399LOWCVSS 3.7EG 3.72026-09-28
The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the…
- CVE-2025-47295LOWCVSS 3.7EG 3.72025-05-28
A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, unde…
- CVE-2026-101130LOWCVSS 3.6EG 3.62026-10-09
The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing arrays of strings in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Aff…
- CVE-2026-101094LOWCVSS 3.6EG 3.62026-10-09
The Affinity by Canva application before 3.3.1 (October 2026 release) did not correctly handle incomplete UTF-8 character sequences when parsing text in Affinity document files, leading to a heap buffer over-read. A threat actor could craf…
- CVE-2026-40341LOWCVSS 3.5EG 3.52026-04-18
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b3…
- CVE-2026-90610LOWCVSS 3.3EG 3.32026-09-14
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only p…
- CVE-2023-53159LOWCVSS 3.3EG 3.32025-07-28
The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
- CVE-2022-42758LOWCVSS 3.3EG 3.32022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2022-42757LOWCVSS 3.3EG 3.32022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2019-1010220LOWCVSS 3.3EG 3.32019-07-22
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", …
- CVE-2026-47088LOWCVSS 3.1EG 3.12026-07-16
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When…
- CVE-2026-96394LOWCVSS 2.9EG 2.92026-10-09
The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews of Affinity document files, leading to a…
- CVE-2024-42333LOWCVSS 2.7EG 2.72024-11-27
The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read in src/libs/zbxmedia/email.c
- CVE-2026-70652LOWCVSS 2.0EG 2.02026-08-20
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr…
- CVE-2025-11961LOWCVSS 1.9EG 1.92025-12-31
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement ha…
- CVE-2024-12975LOWCVSS 1.0EG 1.02025-03-07
A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.
Map vulnerabilities like CWE-126 to your infrastructure
EchelonGraph correlates every CVE — across CWE-126 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →