CWE-126— Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.— MITRE CWE catalog
544 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-126page 2 of 11
- CVE-2023-24849HIGHCVSS 8.2EG 8.22023-10-03
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
- CVE-2023-24848HIGHCVSS 8.2EG 8.22023-10-03
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
- CVE-2023-22385HIGHCVSS 8.2EG 8.22023-10-03
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
- CVE-2023-21625HIGHCVSS 8.2EG 8.22023-08-08
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
- CVE-2023-21669HIGHCVSS 8.2EG 8.22023-06-06
Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.
- CVE-2022-40505HIGHCVSS 8.2EG 8.22023-05-02
Information disclosure due to buffer over-read in Modem while parsing DNS hostname.
- CVE-2022-40503HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
- CVE-2022-33295HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length.
- CVE-2022-33291HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.
- CVE-2022-33287HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet.
- CVE-2022-33258HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure due to buffer over-read in modem while reading configuration parameters.
- CVE-2022-33228HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination option in header.
- CVE-2022-33222HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure due to buffer over-read while parsing DNS response packets in Modem.
- CVE-2022-25747HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message
- CVE-2022-25730HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure in modem due to improper check of IP type while processing DNS server query
- CVE-2022-25726HIGHCVSS 8.2EG 8.22023-04-13
Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet
- CVE-2022-33271HIGHCVSS 8.2EG 8.22023-02-12
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
- CVE-2022-33229HIGHCVSS 8.2EG 8.22023-02-12
Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets.
- CVE-2022-25738HIGHCVSS 8.2EG 8.22023-02-12
Information disclosure in modem due to buffer over-red while performing checksum of packet received
- CVE-2022-25732HIGHCVSS 8.2EG 8.22023-02-12
Information disclosure in modem due to buffer over read in dns client due to missing length check
- CVE-2022-25728HIGHCVSS 8.2EG 8.22023-02-12
Information disclosure in modem due to buffer over-read while processing response from DNS server
- CVE-2023-23571HIGHCVSS 7.5EG 8.22023-07-06
An access violation vulnerability exists in the eventcore functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to denial of service. An attacker can send a network request to trigger this vulnerability.
- CVE-2017-7668HIGHCVSS 7.5EG 8.22017-06-20
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers,…
- CVE-2026-25646HIGHCVSS 8.1EG 8.12026-02-10
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function.…
- CVE-2022-1987HIGHCVSS 8.1EG 8.12022-06-03
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
- CVE-2022-1908HIGHCVSS 8.1EG 8.12022-05-27
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
- CVE-2022-1907HIGHCVSS 8.1EG 8.12022-05-27
Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
- CVE-2026-28364HIGHCVSS 7.8EG 7.92026-02-27
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the r…
- CVE-2026-69582HIGHCVSS 7.8EG 7.82026-09-08
Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-68875HIGHCVSS 7.8EG 7.82026-09-08
Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.
- CVE-2026-64905HIGHCVSS 7.8EG 7.82026-08-11
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-57968HIGHCVSS 7.8EG 7.82026-07-14
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
- CVE-2026-55036HIGHCVSS 7.8EG 7.82026-07-14
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-50435HIGHCVSS 7.8EG 7.82026-07-14
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- CVE-2026-50402HIGHCVSS 7.8EG 7.82026-07-14
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
- CVE-2026-21379HIGHCVSS 7.8EG 7.82026-07-06
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
- CVE-2026-42828HIGHCVSS 7.8EG 7.82026-06-09
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-34336HIGHCVSS 7.8EG 7.82026-05-12
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- CVE-2026-26184HIGHCVSS 7.8EG 7.82026-04-14
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-21378HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
- CVE-2026-21376HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
- CVE-2026-21375HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
- CVE-2026-21374HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
- CVE-2026-21373HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
- CVE-2026-21371HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when retrieving output buffer with insufficient size validation.
- CVE-2025-47390HIGHCVSS 7.8EG 7.82026-04-06
Memory corruption while preprocessing IOCTL request in JPEG driver.
- CVE-2025-59600HIGHCVSS 7.8EG 7.82026-03-02
Memory Corruption when adding user-supplied data without checking available buffer space.
- CVE-2025-62560HIGHCVSS 7.8EG 7.82025-12-09
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-62467HIGHCVSS 7.8EG 7.82025-12-09
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- CVE-2025-62464HIGHCVSS 7.8EG 7.82025-12-09
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Map vulnerabilities like CWE-126 to your infrastructure
EchelonGraph correlates every CVE — across CWE-126 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →