CWE-805— Buffer Access with Incorrect Length Value
The product uses a sequential operation to read or write a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer.— MITRE CWE catalog
58 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-805page 2 of 2
- CVE-2024-34476MEDIUMCVSS 5.3EG 5.32024-05-05
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.
- CVE-2022-34399MEDIUMCVSS 5.1EG 5.12023-01-18
Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a buffer access vulnerability. A malicious user with admin privileges could potentially exploit this vulnerability by sending input larger than expected in order to leak certain se…
- CVE-2026-53877MEDIUMCVSS 4.8EG 4.82026-07-07
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degrad…
- CVE-2026-12549MEDIUMCVSS 4.8EG 4.82026-06-22
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulti…
- CVE-2026-0716MEDIUMCVSS 4.8EG 4.82026-01-13
A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. T…
- CVE-2024-0131MEDIUMCVSS 4.4EG 4.42025-02-02
NVIDIA GPU kernel driver for Windows and Linux contains a vulnerability where a potential user-mode attacker could read a buffer with an incorrect length. A successful exploit of this vulnerability might lead to denial of service.
- CVE-2025-7048MEDIUMCVSS 4.3EG 4.32026-01-06
On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer …
- CVE-2026-15028LOWCVSS 3.9EG 3.92026-07-10
A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.ho…
Map vulnerabilities like CWE-805 to your infrastructure
EchelonGraph correlates every CVE — across CWE-805 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →