VYPR

CWE-126

Buffer Over-read

VariantDraft

Description

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (529)

page 13 of 27
  • CVE-2025-4582HigSep 23, 2025
    risk 0.46cvss 7.1epss 0.00

    Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6.1.0 before 6.1.2.26, from 6.0.0 before…

  • CVE-2024-21462HigJul 1, 2024
    risk 0.46cvss 7.1epss 0.00

    Transient DOS while loading the TA ELF file.

  • CVE-2024-26243HigApr 9, 2024
    risk 0.46cvss 7.0epss 0.00

    Windows USB Print Driver Elevation of Privilege Vulnerability

  • CVE-2023-33060HigFeb 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Transient DOS in Core when DDR memory check is called while DDR is not initialized.

  • CVE-2009-2495MedJul 29, 2009
    risk 0.45cvss 6.5epss 0.34

    The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via…

  • CVE-2025-53736MedAug 12, 2025
    risk 0.44cvss 6.8epss 0.01

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2024-45568MedMay 6, 2025
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to improper bounds check while command handling in camera-kernel driver.

  • CVE-2024-33061MedJan 6, 2025
    risk 0.44cvss 6.8epss 0.00

    Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.

  • CVE-2023-43527MedMay 6, 2024
    risk 0.44cvss 6.8epss 0.00

    Information disclosure while parsing dts header atom in Video.

  • CVE-2024-3077MedMar 29, 2024
    risk 0.44cvss 6.8epss 0.00

    An malicious BLE device can crash BLE victim device by sending malformed gatt packet

  • CVE-2022-40524MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.

  • CVE-2022-33297MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure due to buffer overread in Linux sensors

  • CVE-2022-33221MedFeb 12, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure in Trusted Execution Environment due to buffer over-read while processing metadata verification requests.

  • CVE-2023-0396MedJan 25, 2023
    risk 0.44cvss 6.8epss 0.00

    A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command responses.

  • CVE-2022-4435MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4434MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4433MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4432MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2026-26282MedFeb 19, 2026
    risk 0.43cvss 6.6epss 0.00

    NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap…

  • CVE-2024-23366MedJan 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.