CWE-126— Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.— MITRE CWE catalog
544 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-126page 4 of 11
- CVE-2026-57546HIGHCVSS 7.5EG 7.52026-10-06
Transient DOS when processing a continuous receive command with a zero-sized global configuration override.
- CVE-2026-102728HIGHCVSS 7.5EG 7.52026-09-29
Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both…
- CVE-2026-102758HIGHCVSS 7.5EG 7.52026-09-29
The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates suppl…
- CVE-2026-86243HIGHCVSS 7.5EG 7.52026-09-23
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Ear…
- CVE-2026-25275HIGHCVSS 7.5EG 7.52026-09-17
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
- CVE-2026-72932HIGHCVSS 7.5EG 7.52026-09-08
Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.
- CVE-2026-84640HIGHCVSS 7.5EG 7.52026-09-01
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- CVE-2026-53587HIGHCVSS 7.5EG 7.52026-08-20
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in s…
- CVE-2026-68819HIGHCVSS 7.5EG 7.52026-08-11
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
- CVE-2026-50504HIGHCVSS 7.5EG 7.52026-07-14
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- CVE-2026-50445HIGHCVSS 7.5EG 7.52026-07-14
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-41992HIGHCVSS 7.5EG 7.52026-06-29
GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array th…
- CVE-2025-47403HIGHCVSS 7.5EG 7.52026-05-04
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
- CVE-2025-47401HIGHCVSS 7.5EG 7.52026-05-04
Transient DOS when processing target power rate tables during channel configuration.
- CVE-2026-34059HIGHCVSS 7.5EG 7.52026-05-04
Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- CVE-2026-3203HIGHCVSS 7.5EG 7.52026-02-25
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
- CVE-2026-20846HIGHCVSS 7.5EG 7.52026-02-10
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
- CVE-2025-66692HIGHCVSS 7.5EG 7.52026-01-20
A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2025-60003HIGHCVSS 7.5EG 7.52026-01-15
A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives…
- CVE-2025-62792HIGHCVSS 7.5EG 7.52025-10-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not b…
- CVE-2025-62787HIGHCVSS 7.5EG 7.52025-10-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) i…
- CVE-2025-47328HIGHCVSS 7.5EG 7.52025-09-24
Transient DOS while processing power control requests with invalid antenna or stream values.
- CVE-2025-47326HIGHCVSS 7.5EG 7.52025-09-24
Transient DOS while handling command data during power control processing.
- CVE-2025-47318HIGHCVSS 7.5EG 7.52025-09-24
Transient DOS while parsing the EPTM test control message to get the test pattern.
- CVE-2025-27065HIGHCVSS 7.5EG 7.52025-08-06
Transient DOS while processing a frame with malformed shared-key descriptor.
- CVE-2025-27057HIGHCVSS 7.5EG 7.52025-07-08
Transient DOS while handling beacon frames with invalid IE header length.
- CVE-2025-21454HIGHCVSS 7.5EG 7.52025-07-08
Transient DOS while processing received beacon frame.
- CVE-2025-21449HIGHCVSS 7.5EG 7.52025-07-08
Transient DOS may occur while processing malformed length field in SSID IEs.
- CVE-2025-21446HIGHCVSS 7.5EG 7.52025-07-08
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
- CVE-2025-27029HIGHCVSS 7.5EG 7.52025-06-03
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
- CVE-2025-21463HIGHCVSS 7.5EG 7.52025-06-03
Transient DOS while processing the EHT operation IE in the received beacon frame.
- CVE-2024-52879HIGHCVSS 7.5EG 7.52025-05-15
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 …
- CVE-2024-52878HIGHCVSS 7.5EG 7.52025-05-15
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 …
- CVE-2024-52877HIGHCVSS 7.5EG 7.52025-05-15
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 …
- CVE-2025-21459HIGHCVSS 7.5EG 7.52025-05-06
Transient DOS while parsing per STA profile in ML IE.
- CVE-2024-49847HIGHCVSS 7.5EG 7.52025-05-06
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
- CVE-2025-21448HIGHCVSS 7.5EG 7.52025-04-07
Transient DOS may occur while parsing SSID in action frames.
- CVE-2025-21435HIGHCVSS 7.5EG 7.52025-04-07
Transient DOS may occur while parsing extended IE in beacon.
- CVE-2025-21434HIGHCVSS 7.5EG 7.52025-04-07
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
- CVE-2025-21430HIGHCVSS 7.5EG 7.52025-04-07
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- CVE-2025-21429HIGHCVSS 7.5EG 7.52025-04-07
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
- CVE-2025-21428HIGHCVSS 7.5EG 7.52025-04-07
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
- CVE-2024-38404HIGHCVSS 7.5EG 7.52025-02-03
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
- CVE-2024-45558HIGHCVSS 7.5EG 7.52025-01-06
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
- CVE-2024-38405HIGHCVSS 7.5EG 7.52024-11-04
Transient DOS while processing the CU information from RNR IE.
- CVE-2024-38403HIGHCVSS 7.5EG 7.52024-11-04
Transient DOS while parsing BTM ML IE when per STA profile is not included.
- CVE-2024-38397HIGHCVSS 7.5EG 7.52024-10-07
Transient DOS while parsing probe response and assoc response frame.
- CVE-2024-33071HIGHCVSS 7.5EG 7.52024-10-07
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
- CVE-2024-33070HIGHCVSS 7.5EG 7.52024-10-07
Transient DOS while parsing ESP IE from beacon/probe response frame.
- CVE-2024-33049HIGHCVSS 7.5EG 7.52024-10-07
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Map vulnerabilities like CWE-126 to your infrastructure
EchelonGraph correlates every CVE — across CWE-126 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →