CWE-126— Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.— MITRE CWE catalog
544 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-126page 7 of 11
- CVE-2023-43527MEDIUMCVSS 6.8EG 6.82024-05-06
Information disclosure while parsing dts header atom in Video.
- CVE-2024-3077MEDIUMCVSS 6.8EG 6.82024-03-29
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
- CVE-2022-33297MEDIUMCVSS 6.8EG 6.82023-04-13
Information disclosure due to buffer overread in Linux sensors
- CVE-2022-33221MEDIUMCVSS 6.8EG 6.82023-02-12
Information disclosure in Trusted Execution Environment due to buffer over-read while processing metadata verification requests.
- CVE-2023-0396MEDIUMCVSS 6.8EG 6.82023-01-25
A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command responses.
- CVE-2024-45568MEDIUMCVSS 6.7EG 6.72025-05-06
Memory corruption due to improper bounds check while command handling in camera-kernel driver.
- CVE-2022-40524MEDIUMCVSS 6.7EG 6.72023-09-05
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
- CVE-2022-4435MEDIUMCVSS 6.7EG 6.72023-01-05
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
- CVE-2022-4434MEDIUMCVSS 6.7EG 6.72023-01-05
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.
- CVE-2022-4433MEDIUMCVSS 6.7EG 6.72023-01-05
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
- CVE-2022-4432MEDIUMCVSS 6.7EG 6.72023-01-05
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
- CVE-2009-2495MEDIUMCVSS 6.5EG 6.72009-07-29
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attac…
- CVE-2026-26282MEDIUMCVSS 6.6EG 6.62026-02-19
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file wi…
- CVE-2024-23366MEDIUMCVSS 6.6EG 6.62025-01-06
Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.
- CVE-2026-72974MEDIUMCVSS 6.5EG 6.52026-09-08
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- CVE-2026-69626MEDIUMCVSS 6.5EG 6.52026-09-08
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
- CVE-2026-67393MEDIUMCVSS 6.5EG 6.52026-09-08
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-67390MEDIUMCVSS 6.5EG 6.52026-09-08
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-73029MEDIUMCVSS 6.5EG 6.52026-09-08
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-69719MEDIUMCVSS 6.5EG 6.52026-09-08
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
- CVE-2026-76885MEDIUMCVSS 6.5EG 6.52026-08-19
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-76884MEDIUMCVSS 6.5EG 6.52026-08-19
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-69550MEDIUMCVSS 6.5EG 6.52026-08-19
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- CVE-2026-65794MEDIUMCVSS 6.5EG 6.52026-08-11
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
- CVE-2026-53414MEDIUMCVSS 6.5EG 6.52026-08-11
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
- CVE-2026-55970MEDIUMCVSS 6.5EG 6.52026-07-27
Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
- CVE-2026-63091MEDIUMCVSS 6.5EG 6.52026-07-20
ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of U…
- CVE-2026-50468MEDIUMCVSS 6.5EG 6.52026-07-14
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-6238MEDIUMCVSS 6.5EG 6.52026-04-28
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG rec…
- CVE-2026-26155MEDIUMCVSS 6.5EG 6.52026-04-14
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- CVE-2026-2394MEDIUMCVSS 6.5EG 6.52026-04-01
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before…
- CVE-2025-47402MEDIUMCVSS 6.5EG 6.52026-02-02
Transient DOS when processing a received frame with an excessively large authentication information element.
- CVE-2025-47395MEDIUMCVSS 6.5EG 6.52026-01-07
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
- CVE-2025-62473MEDIUMCVSS 6.5EG 6.52025-12-09
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-55091MEDIUMCVSS 6.5EG 6.52025-10-16
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when received an Ethernet with type set as IP but no IP data.
- CVE-2025-55090MEDIUMCVSS 6.5EG 6.52025-10-16
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4 bytes of IP packet.
- CVE-2025-53806MEDIUMCVSS 6.5EG 6.52025-09-09
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-53798MEDIUMCVSS 6.5EG 6.52025-09-09
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-53797MEDIUMCVSS 6.5EG 6.52025-09-09
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-53796MEDIUMCVSS 6.5EG 6.52025-09-09
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-26676MEDIUMCVSS 6.5EG 6.52025-04-08
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-26672MEDIUMCVSS 6.5EG 6.52025-04-08
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-26664MEDIUMCVSS 6.5EG 6.52025-04-08
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-21203MEDIUMCVSS 6.5EG 6.52025-04-08
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-32053MEDIUMCVSS 6.5EG 6.52025-04-03
A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read.
- CVE-2025-32052MEDIUMCVSS 6.5EG 6.52025-04-03
A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read.
- CVE-2024-43595MEDIUMCVSS 6.5EG 6.52024-10-17
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2024-21467MEDIUMCVSS 6.5EG 6.52024-08-05
Information disclosure while handling beacon probe frame during scan entry generation in client side.
- CVE-2024-21459MEDIUMCVSS 6.5EG 6.52024-08-05
Information disclosure while handling beacon or probe response frame in STA.
- CVE-2024-21458MEDIUMCVSS 6.5EG 6.52024-07-01
Information disclosure while handling SA query action frame.
Map vulnerabilities like CWE-126 to your infrastructure
EchelonGraph correlates every CVE — across CWE-126 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →