CWE-126— Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.— MITRE CWE catalog
544 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-126page 6 of 11
- CVE-2023-21658HIGHCVSS 7.5EG 7.52023-06-06
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
- CVE-2023-24942HIGHCVSS 7.5EG 7.52023-05-09
Remote Procedure Call Runtime Denial of Service Vulnerability
- CVE-2023-24901HIGHCVSS 7.5EG 7.52023-05-09
Windows NFS Portmapper Information Disclosure Vulnerability
- CVE-2023-24858HIGHCVSS 7.5EG 7.52023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- CVE-2022-40535HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS due to buffer over-read in WLAN while sending a packet to device.
- CVE-2022-33309HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS due to buffer over-read in WLAN Firmware while parsing secure FTMR frame with size lesser than 39 Bytes.
- CVE-2023-21813HIGHCVSS 7.5EG 7.52023-02-14
Windows Secure Channel Denial of Service Vulnerability
- CVE-2023-21811HIGHCVSS 7.5EG 7.52023-02-14
Windows iSCSI Service Denial of Service Vulnerability
- CVE-2023-21701HIGHCVSS 7.5EG 7.52023-02-14
Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability
- CVE-2022-40512HIGHCVSS 7.5EG 7.52023-02-12
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
- CVE-2022-34145HIGHCVSS 7.5EG 7.52023-02-12
Transient DOS due to buffer over-read in WLAN Host while parsing frame information.
- CVE-2022-33306HIGHCVSS 7.5EG 7.52023-02-12
Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs.
- CVE-2022-22519HIGHCVSS 7.5EG 7.52022-04-07
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
- CVE-2020-25853HIGHCVSS 7.5EG 7.52021-02-03
The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, _rt_md5_hmac_veneer() or _rt_hmac_sha1_veneer()…
- CVE-2019-5432HIGHCVSS 7.5EG 7.52019-05-06
A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.
- CVE-2018-8799HIGHCVSS 7.5EG 7.52019-02-05
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).
- CVE-2018-8798HIGHCVSS 7.5EG 7.52019-02-05
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak.
- CVE-2018-8796HIGHCVSS 7.5EG 7.52019-02-05
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (segfault).
- CVE-2018-8792HIGHCVSS 7.5EG 7.52019-02-05
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that results in a Denial of Service (segfault).
- CVE-2018-8791HIGHCVSS 7.5EG 7.52019-02-05
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak.
- CVE-2018-8789HIGHCVSS 7.5EG 7.52018-11-29
FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).
- CVE-2023-24513HIGHCVSS 6.5EG 7.52023-04-12
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough …
- CVE-2026-25294HIGHCVSS 7.4EG 7.42026-09-17
Transient DOS while parsing frame during channel usage.
- CVE-2026-24081HIGHCVSS 7.4EG 7.42026-09-17
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
- CVE-2026-25288HIGHCVSS 7.4EG 7.42026-08-04
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
- CVE-2026-4371HIGHCVSS 7.4EG 7.42026-03-24
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfu…
- CVE-2023-20112HIGHCVSS 7.4EG 7.42023-03-23
A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain param…
- CVE-2023-21820HIGHCVSS 7.4EG 7.42023-02-14
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
- CVE-2026-25284HIGHCVSS 7.3EG 7.32026-09-17
Information Disclosure when a pointer is reused after being deallocated.
- CVE-2026-44185HIGHCVSS 7.3EG 7.32026-06-08
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, w…
- CVE-2025-63602HIGHCVSS 7.3EG 7.32025-11-18
A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0…
- CVE-2024-43475HIGHCVSS 7.3EG 7.32024-09-10
Microsoft Windows Admin Center Information Disclosure Vulnerability
- CVE-2024-31082HIGHCVSS 7.3EG 7.32024-04-04
A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation …
- CVE-2024-31081HIGHCVSS 7.3EG 7.32024-04-04
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation f…
- CVE-2024-31080HIGHCVSS 7.3EG 7.32024-04-04
A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation f…
- CVE-2022-33273HIGHCVSS 7.3EG 7.32023-05-02
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
- CVE-2026-94286HIGHCVSS 7.1EG 7.12026-09-28
An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.
- CVE-2026-37532HIGHCVSS 7.1EG 7.12026-05-01
AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_receive (receive.c:87-89), the payload_length for a Single Frame is extracted from a 4-bit nibble in the CAN frame data, …
- CVE-2025-47400HIGHCVSS 7.1EG 7.12026-04-06
Cryptographic issue while copying data to a destination buffer without validating its size.
- CVE-2026-27798HIGHCVSS 7.1EG 7.12026-02-26
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small dimension using the `…
- CVE-2025-4582HIGHCVSS 7.1EG 7.12025-09-23
Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6.1…
- CVE-2024-21462HIGHCVSS 7.1EG 7.12024-07-01
Transient DOS while loading the TA ELF file.
- CVE-2023-33060HIGHCVSS 7.1EG 7.12024-02-06
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
- CVE-2022-1534HIGHCVSS 7.1EG 7.12022-04-29
Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information fr…
- CVE-2026-69610HIGHCVSS 7.0EG 7.02026-09-08
Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.
- CVE-2026-50372HIGHCVSS 7.0EG 7.02026-07-14
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
- CVE-2024-26243HIGHCVSS 7.0EG 7.02024-04-09
Windows USB Print Driver Elevation of Privilege Vulnerability
- CVE-2025-66038MEDIUMCVSS 6.8EG 6.82026-03-30
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length (low nibb…
- CVE-2025-53736MEDIUMCVSS 6.8EG 6.82025-08-12
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2024-33061MEDIUMCVSS 6.8EG 6.82025-01-06
Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.
Map vulnerabilities like CWE-126 to your infrastructure
EchelonGraph correlates every CVE — across CWE-126 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →