CWE-126— Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.— MITRE CWE catalog
544 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-126page 9 of 11
- CVE-2023-4758MEDIUMCVSS 5.5EG 5.92023-09-04
Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV.
- CVE-2025-7745MEDIUMCVSS 5.8EG 5.82025-07-24
Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
- CVE-2026-69416MEDIUMCVSS 5.7EG 5.72026-09-08
Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
- CVE-2026-50485MEDIUMCVSS 5.7EG 5.72026-07-14
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
- CVE-2024-11596MEDIUMCVSS 7.8EG 5.52024-11-21
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
- CVE-2026-95392MEDIUMCVSS 5.5EG 5.52026-09-29
MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-96420MEDIUMCVSS 5.5EG 5.52026-09-29
Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-83949MEDIUMCVSS 5.5EG 5.52026-09-08
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-83951MEDIUMCVSS 5.5EG 5.52026-09-08
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-81399MEDIUMCVSS 5.5EG 5.52026-09-08
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-69794MEDIUMCVSS 5.5EG 5.52026-09-08
Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
- CVE-2026-68851MEDIUMCVSS 5.5EG 5.52026-09-08
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
- CVE-2026-62793MEDIUMCVSS 5.5EG 5.52026-08-11
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
- CVE-2026-62730MEDIUMCVSS 5.5EG 5.52026-08-11
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
- CVE-2026-62746MEDIUMCVSS 5.5EG 5.52026-08-11
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
- CVE-2026-61347MEDIUMCVSS 5.5EG 5.52026-08-11
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
- CVE-2026-50475MEDIUMCVSS 5.5EG 5.52026-07-14
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-50341MEDIUMCVSS 5.5EG 5.52026-07-14
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
- CVE-2025-59609MEDIUMCVSS 5.5EG 5.52026-06-01
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
- CVE-2026-6532MEDIUMCVSS 5.5EG 5.52026-04-30
Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- CVE-2025-47330MEDIUMCVSS 5.5EG 5.52026-01-07
Transient DOS while parsing video packets received from the video firmware.
- CVE-2025-55325MEDIUMCVSS 5.5EG 5.52025-10-14
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- CVE-2025-27049MEDIUMCVSS 5.5EG 5.52025-10-09
Transient DOS while processing IOCTL call for image encoding.
- CVE-2025-27041MEDIUMCVSS 5.5EG 5.52025-10-09
Transient DOS while processing video packets received from video firmware.
- CVE-2025-54901MEDIUMCVSS 5.5EG 5.52025-09-09
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2025-49684MEDIUMCVSS 5.5EG 5.52025-07-08
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
- CVE-2025-24068MEDIUMCVSS 5.5EG 5.52025-06-10
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- CVE-2025-24992MEDIUMCVSS 5.5EG 5.52025-03-11
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
- CVE-2024-43056MEDIUMCVSS 5.5EG 5.52025-03-03
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
- CVE-2024-45559MEDIUMCVSS 5.5EG 5.52025-01-06
Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.
- CVE-2024-43500MEDIUMCVSS 5.5EG 5.52024-10-08
Windows Resilient File System (ReFS) Information Disclosure Vulnerability
- CVE-2024-33043MEDIUMCVSS 5.5EG 5.52024-09-02
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
- CVE-2024-30039MEDIUMCVSS 5.5EG 5.52024-05-14
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- CVE-2024-28902MEDIUMCVSS 5.5EG 5.52024-04-09
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- CVE-2024-28901MEDIUMCVSS 5.5EG 5.52024-04-09
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- CVE-2024-28900MEDIUMCVSS 5.5EG 5.52024-04-09
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- CVE-2024-26255MEDIUMCVSS 5.5EG 5.52024-04-09
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- CVE-2024-26160MEDIUMCVSS 5.5EG 5.52024-03-12
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
- CVE-2023-33090MEDIUMCVSS 5.5EG 5.52024-03-04
Transient DOS while processing channel information for speaker protection v2 module in ADSP.
- CVE-2023-33064MEDIUMCVSS 5.5EG 5.52024-02-06
Transient DOS in Audio when invoking callback function of ASM driver.
- CVE-2023-6992MEDIUMCVSS 5.5EG 5.52024-01-04
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A lo…
- CVE-2023-36803MEDIUMCVSS 5.5EG 5.52023-09-12
Windows Kernel Information Disclosure Vulnerability
- CVE-2023-35324MEDIUMCVSS 5.5EG 5.52023-07-11
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- CVE-2023-32085MEDIUMCVSS 5.5EG 5.52023-07-11
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- CVE-2023-28266MEDIUMCVSS 5.5EG 5.52023-04-11
Windows Common Log File System Driver Information Disclosure Vulnerability
- CVE-2022-44446MEDIUMCVSS 5.5EG 5.52023-01-04
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-44445MEDIUMCVSS 5.5EG 5.52023-01-04
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-44443MEDIUMCVSS 5.5EG 5.52023-01-04
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-42781MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
- CVE-2022-42780MEDIUMCVSS 5.5EG 5.52022-12-06
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
Map vulnerabilities like CWE-126 to your infrastructure
EchelonGraph correlates every CVE — across CWE-126 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →