VYPR

CWE-126

Buffer Over-read

VariantDraft

Description

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (492)

page 13 of 25
  • CVE-2022-40524MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.

  • CVE-2022-33297MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure due to buffer overread in Linux sensors

  • CVE-2022-33221MedFeb 12, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure in Trusted Execution Environment due to buffer over-read while processing metadata verification requests.

  • CVE-2023-0396MedJan 25, 2023
    risk 0.44cvss 6.8epss 0.00

    A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command responses.

  • CVE-2022-4435MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4434MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4433MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2022-4432MedJan 5, 2023
    risk 0.44cvss 6.7epss 0.00

    A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.

  • CVE-2026-26282MedFeb 19, 2026
    risk 0.43cvss 6.6epss 0.00

    NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap…

  • CVE-2024-23366MedJan 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.

  • CVE-2023-28572MedNov 7, 2023
    risk 0.43cvss 6.6epss 0.00

    Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.

  • CVE-2026-65794MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-53414MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

  • CVE-2026-66312MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

  • CVE-2025-47403MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

  • CVE-2025-47401MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing target power rate tables during channel configuration.

  • CVE-2026-34059HigMay 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

  • CVE-2026-6238MedApr 28, 2026
    risk 0.42cvss 6.5epss 0.00

    The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to…

  • CVE-2026-26155MedApr 14, 2026
    risk 0.42cvss 6.5epss 0.01

    Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

  • CVE-2026-2394MedApr 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from…