VYPR

CWE-126

Buffer Over-read

VariantDraft

Description

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (492)

page 12 of 25
  • CVE-2024-43475HigSep 10, 2024
    risk 0.48cvss 7.3epss 0.02

    Microsoft Windows Admin Center Information Disclosure Vulnerability

  • CVE-2023-20112HigMar 23, 2023
    risk 0.48cvss 7.4epss 0.00

    A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain parameters within 802.11 frames. An attacker…

  • CVE-2023-21820HigFeb 14, 2023
    risk 0.48cvss 7.4epss 0.01

    Windows Distributed File System (DFS) Remote Code Execution Vulnerability

  • CVE-2025-63602HigNov 18, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0.5, renamed to…

  • CVE-2024-31082HigApr 4, 2024
    risk 0.47cvss 7.3epss 0.00

    A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a…

  • CVE-2024-31081HigApr 4, 2024
    risk 0.47cvss 7.3epss 0.01

    A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a…

  • CVE-2024-31080HigApr 4, 2024
    risk 0.47cvss 7.3epss 0.01

    A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a…

  • CVE-2022-33273HigMay 2, 2023
    risk 0.47cvss 7.3epss 0.00

    Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.

  • CVE-2026-37532HigMay 1, 2026
    risk 0.46cvss 7.1epss 0.00

    AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_receive (receive.c:87-89), the payload_length for a Single Frame is extracted from a 4-bit nibble in the CAN frame data, yielding values 0-15. However, a…

  • CVE-2025-47400HigApr 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue while copying data to a destination buffer without validating its size.

  • CVE-2025-4582HigSep 23, 2025
    risk 0.46cvss 7.1epss 0.00

    Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6.1.0 before 6.1.2.26, from 6.0.0 before…

  • CVE-2024-21462HigJul 1, 2024
    risk 0.46cvss 7.1epss 0.00

    Transient DOS while loading the TA ELF file.

  • CVE-2024-26243HigApr 9, 2024
    risk 0.46cvss 7.0epss 0.00

    Windows USB Print Driver Elevation of Privilege Vulnerability

  • CVE-2023-33060HigFeb 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Transient DOS in Core when DDR memory check is called while DDR is not initialized.

  • CVE-2009-2495MedJul 29, 2009
    risk 0.45cvss 6.5epss 0.34

    The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via…

  • CVE-2025-53736MedAug 12, 2025
    risk 0.44cvss 6.8epss 0.01

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2024-45568MedMay 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to improper bounds check while command handling in camera-kernel driver.

  • CVE-2024-33061MedJan 6, 2025
    risk 0.44cvss 6.8epss 0.00

    Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.

  • CVE-2023-43527MedMay 6, 2024
    risk 0.44cvss 6.8epss 0.00

    Information disclosure while parsing dts header atom in Video.

  • CVE-2024-3077MedMar 29, 2024
    risk 0.44cvss 6.8epss 0.00

    An malicious BLE device can crash BLE victim device by sending malformed gatt packet