VYPR

CWE-126

Buffer Over-read

VariantDraft

Description

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (529)

page 14 of 27
  • CVE-2023-28572MedNov 7, 2023
    risk 0.43cvss 6.6epss 0.00

    Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.

  • CVE-2026-73029MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

  • CVE-2026-72974MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-69719MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-69626MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-67393MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

  • CVE-2026-67390MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

  • CVE-2026-53587HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.00

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in…

  • CVE-2026-69550MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-65794MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-53414MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

  • CVE-2026-66312MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

  • CVE-2025-47403MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

  • CVE-2025-47401MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing target power rate tables during channel configuration.

  • CVE-2026-34059HigMay 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

  • CVE-2026-6238MedApr 28, 2026
    risk 0.42cvss 6.5epss 0.00

    The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to…

  • CVE-2026-26155MedApr 14, 2026
    risk 0.42cvss 6.5epss 0.01

    Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

  • CVE-2026-2394MedApr 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from…

  • CVE-2025-47402MedFeb 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing a received frame with an excessively large authentication information element.

  • CVE-2025-47395MedJan 7, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.