CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (492)
page 15 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21456 | Med | 0.42 | 6.5 | 0.00 | Jul 1, 2024 | Information Disclosure while parsing beacon frame in STA. | ||
| CVE-2023-43537 | Med | 0.42 | 6.5 | 0.00 | Jun 3, 2024 | Information disclosure while handling T2LM Action Frame in WLAN Host. | ||
| CVE-2023-21667 | Med | 0.42 | 6.5 | 0.00 | Sep 5, 2023 | Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard. | ||
| CVE-2023-33173 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2023-33172 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2023-33169 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2023-33168 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2023-33167 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2023-33166 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Remote Procedure Call Runtime Denial of Service Vulnerability | ||
| CVE-2023-24513 | Med | 0.42 | 6.5 | 0.01 | Apr 12, 2023 | On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the… | ||
| CVE-2023-28267 | Med | 0.42 | 6.5 | 0.02 | Apr 11, 2023 | Remote Desktop Protocol Client Information Disclosure Vulnerability | ||
| CVE-2023-24883 | Med | 0.42 | 6.5 | 0.01 | Apr 11, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2023-24870 | Med | 0.42 | 6.5 | 0.01 | Mar 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2023-24857 | Med | 0.42 | 6.5 | 0.01 | Mar 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2022-32141 | Med | 0.42 | 6.5 | 0.01 | Jun 24, 2022 | Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required. | ||
| CVE-2026-20311 | Med | 0.41 | 6.3 | 0.00 | Aug 5, 2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the… | ||
| CVE-2026-44185 | Hig | 0.41 | 7.3 | 0.01 | Jun 8, 2026 | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | ||
| CVE-2025-47406 | Med | 0.40 | 6.1 | 0.00 | May 4, 2026 | Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. | ||
| CVE-2026-26169 | Med | 0.40 | 6.1 | 0.02 | Apr 14, 2026 | Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally. | ||
| CVE-2025-47331 | Med | 0.40 | 6.1 | 0.00 | Jan 7, 2026 | Information disclosure while processing a firmware event. |
- risk 0.42cvss 6.5epss 0.00
Information Disclosure while parsing beacon frame in STA.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling T2LM Action Frame in WLAN Host.
- risk 0.42cvss 6.5epss 0.00
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
- risk 0.42cvss 6.5epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Remote Procedure Call Runtime Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the…
- risk 0.42cvss 6.5epss 0.02
Remote Desktop Protocol Client Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.
- risk 0.41cvss 6.3epss 0.00
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the…
- risk 0.41cvss 7.3epss 0.01
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
- risk 0.40cvss 6.1epss 0.00
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
- risk 0.40cvss 6.1epss 0.02
Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing a firmware event.