VYPR

CWE-126

Buffer Over-read

VariantDraft

Description

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (529)

page 12 of 27
  • CVE-2022-33306HigFeb 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs.

  • CVE-2022-22519HigApr 7, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.

  • CVE-2020-25853HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.01

    The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, _rt_md5_hmac_veneer() or _rt_hmac_sha1_veneer(), resulting in a stack buffer over-read…

  • CVE-2019-5432HigMay 6, 2019
    risk 0.49cvss 7.5epss 0.02

    A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.

  • CVE-2026-25294HigSep 17, 2026
    risk 0.48cvss 7.4epss 0.00

    Transient DOS while parsing frame during channel usage.

  • CVE-2026-24081HigSep 17, 2026
    risk 0.48cvss 7.4epss 0.00

    Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

  • CVE-2026-25288HigAug 4, 2026
    risk 0.48cvss 7.4epss 0.00

    Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

  • CVE-2026-4371HigMar 24, 2026
    risk 0.48cvss 7.4epss 0.00

    A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird…

  • CVE-2024-43475HigSep 10, 2024
    risk 0.48cvss 7.3epss 0.02

    Microsoft Windows Admin Center Information Disclosure Vulnerability

  • CVE-2023-20112HigMar 23, 2023
    risk 0.48cvss 7.4epss 0.00

    A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker…

  • CVE-2023-21820HigFeb 14, 2023
    risk 0.48cvss 7.4epss 0.01

    Windows Distributed File System (DFS) Remote Code Execution Vulnerability

  • CVE-2026-25284HigSep 17, 2026
    risk 0.47cvss 7.3epss 0.00

    Information Disclosure when a pointer is reused after being deallocated.

  • CVE-2025-63602HigNov 18, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0.5, renamed to…

  • CVE-2024-31082HigApr 4, 2024
    risk 0.47cvss 7.3epss 0.00

    A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a…

  • CVE-2024-31081HigApr 4, 2024
    risk 0.47cvss 7.3epss 0.01

    A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a…

  • CVE-2024-31080HigApr 4, 2024
    risk 0.47cvss 7.3epss 0.01

    A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a…

  • CVE-2022-33273HigMay 2, 2023
    risk 0.47cvss 7.3epss 0.00

    Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.

  • CVE-2026-69610HigSep 8, 2026
    risk 0.46cvss 7.0epss 0.00

    Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-37532HigMay 1, 2026
    risk 0.46cvss 7.1epss 0.00

    AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_receive (receive.c:87-89), the payload_length for a Single Frame is extracted from a 4-bit nibble in the CAN frame data, yielding values 0-15. However, a…

  • CVE-2025-47400HigApr 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue while copying data to a destination buffer without validating its size.