CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (492)
page 11 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21661 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS while parsing WLAN beacon or probe-response frame. | ||
| CVE-2023-21660 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while parsing FT Information Elements. | ||
| CVE-2023-21659 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while processing frames with missing header fields. | ||
| CVE-2023-21658 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS in WLAN Firmware while processing the received beacon or probe response frame. | ||
| CVE-2023-24942 | Hig | 0.49 | 7.5 | 0.02 | May 9, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2023-24901 | Hig | 0.49 | 7.5 | 0.02 | May 9, 2023 | Windows NFS Portmapper Information Disclosure Vulnerability | ||
| CVE-2023-24858 | Hig | 0.49 | 7.5 | 0.01 | Mar 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2022-40535 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | Transient DOS due to buffer over-read in WLAN while sending a packet to device. | ||
| CVE-2022-33309 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | Transient DOS due to buffer over-read in WLAN Firmware while parsing secure FTMR frame with size lesser than 39 Bytes. | ||
| CVE-2023-21813 | Hig | 0.49 | 7.5 | 0.02 | Feb 14, 2023 | Windows Secure Channel Denial of Service Vulnerability | ||
| CVE-2023-21811 | Hig | 0.49 | 7.5 | 0.02 | Feb 14, 2023 | Windows iSCSI Service Denial of Service Vulnerability | ||
| CVE-2023-21701 | Hig | 0.49 | 7.5 | 0.02 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability | ||
| CVE-2022-40512 | Hig | 0.49 | 7.5 | 0.00 | Feb 12, 2023 | Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. | ||
| CVE-2022-34145 | Hig | 0.49 | 7.5 | 0.00 | Feb 12, 2023 | Transient DOS due to buffer over-read in WLAN Host while parsing frame information. | ||
| CVE-2022-33306 | Hig | 0.49 | 7.5 | 0.00 | Feb 12, 2023 | Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs. | ||
| CVE-2022-22519 | Hig | 0.49 | 7.5 | 0.01 | Apr 7, 2022 | A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system. | ||
| CVE-2020-25853 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2021 | The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, _rt_md5_hmac_veneer() or _rt_hmac_sha1_veneer(), resulting in a stack buffer over-read… | ||
| CVE-2019-5432 | Hig | 0.49 | 7.5 | 0.02 | May 6, 2019 | A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding. | ||
| CVE-2026-25288 | Hig | 0.48 | 7.4 | 0.00 | Aug 4, 2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | ||
| CVE-2026-4371 | Hig | 0.48 | 7.4 | 0.00 | Mar 24, 2026 | A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird… |
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing WLAN beacon or probe-response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing FT Information Elements.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while processing frames with missing header fields.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
- risk 0.49cvss 7.5epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows NFS Portmapper Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to buffer over-read in WLAN while sending a packet to device.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to buffer over-read in WLAN Firmware while parsing secure FTMR frame with size lesser than 39 Bytes.
- risk 0.49cvss 7.5epss 0.02
Windows Secure Channel Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows iSCSI Service Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to buffer over-read in WLAN Host while parsing frame information.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs.
- risk 0.49cvss 7.5epss 0.01
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.
- risk 0.49cvss 7.5epss 0.01
The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, _rt_md5_hmac_veneer() or _rt_hmac_sha1_veneer(), resulting in a stack buffer over-read…
- risk 0.49cvss 7.5epss 0.02
A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.
- risk 0.48cvss 7.4epss 0.00
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
- risk 0.48cvss 7.4epss 0.00
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird…