CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (492)
page 17 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28553 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information Disclosure in WLAN Host when processing WMI event command. | ||
| CVE-2023-28571 | Med | 0.40 | 6.1 | 0.00 | Oct 3, 2023 | Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan. | ||
| CVE-2023-21697 | Med | 0.40 | 6.2 | 0.01 | Feb 14, 2023 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | ||
| CVE-2026-68819 | Med | 0.38 | 5.9 | 0.01 | Aug 11, 2026 | Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-7745 | Med | 0.38 | 5.8 | 0.00 | Jul 24, 2025 | Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2. | ||
| CVE-2025-4207 | Med | 0.38 | 5.9 | 0.01 | May 8, 2025 | Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL… | ||
| CVE-2023-39541 | Med | 0.38 | 5.9 | 0.01 | Feb 20, 2024 | A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This… | ||
| CVE-2023-39540 | Med | 0.38 | 5.9 | 0.01 | Feb 20, 2024 | A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This… | ||
| CVE-2022-23130 | Med | 0.38 | 5.9 | 0.01 | Jan 21, 2022 | Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 and prior, Mitsubishi Electric ICONICS Suite versions 10.97… | ||
| CVE-2024-26160 | Med | 0.37 | 5.5 | 0.11 | Mar 12, 2024 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | ||
| CVE-2026-62793 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62746 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62730 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-61347 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59609 | Med | 0.36 | 5.5 | 0.00 | Jun 1, 2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | ||
| CVE-2026-3203 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2026 | RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service | ||
| CVE-2025-47330 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | Transient DOS while parsing video packets received from the video firmware. | ||
| CVE-2025-55325 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-27049 | Med | 0.36 | 5.5 | 0.00 | Oct 9, 2025 | Transient DOS while processing IOCTL call for image encoding. | ||
| CVE-2025-27041 | Med | 0.36 | 5.5 | 0.00 | Oct 9, 2025 | Transient DOS while processing video packets received from video firmware. |
- risk 0.40cvss 6.1epss 0.00
Information Disclosure in WLAN Host when processing WMI event command.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
- risk 0.40cvss 6.2epss 0.01
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
- risk 0.38cvss 5.9epss 0.01
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
- risk 0.38cvss 5.8epss 0.00
Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
- risk 0.38cvss 5.9epss 0.01
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL…
- risk 0.38cvss 5.9epss 0.01
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…
- risk 0.38cvss 5.9epss 0.01
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…
- risk 0.38cvss 5.9epss 0.01
Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 and prior, Mitsubishi Electric ICONICS Suite versions 10.97…
- risk 0.37cvss 5.5epss 0.11
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
- risk 0.36cvss 5.5epss 0.00
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
- risk 0.36cvss 5.5epss 0.00
Transient DOS while parsing video packets received from the video firmware.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while processing IOCTL call for image encoding.
- risk 0.36cvss 5.5epss 0.00
Transient DOS while processing video packets received from video firmware.