CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (492)
page 18 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-54901 | Med | 0.36 | 5.5 | 0.01 | Sep 9, 2025 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-49684 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-24068 | Med | 0.36 | 5.5 | 0.00 | Jun 10, 2025 | Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-24992 | Med | 0.36 | 5.5 | 0.01 | Mar 11, 2025 | Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. | ||
| CVE-2024-43056 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2025 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. | ||
| CVE-2024-45559 | Med | 0.36 | 5.5 | 0.00 | Jan 6, 2025 | Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend. | ||
| CVE-2024-43500 | Med | 0.36 | 5.5 | 0.01 | Oct 8, 2024 | Windows Resilient File System (ReFS) Information Disclosure Vulnerability | ||
| CVE-2024-33043 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. | ||
| CVE-2024-30039 | Med | 0.36 | 5.5 | 0.01 | May 14, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-28902 | Med | 0.36 | 5.5 | 0.01 | Apr 9, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-28901 | Med | 0.36 | 5.5 | 0.01 | Apr 9, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-28900 | Med | 0.36 | 5.5 | 0.01 | Apr 9, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-26255 | Med | 0.36 | 5.5 | 0.01 | Apr 9, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2023-33090 | Med | 0.36 | 5.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing channel information for speaker protection v2 module in ADSP. | ||
| CVE-2023-33064 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2024 | Transient DOS in Audio when invoking callback function of ASM driver. | ||
| CVE-2023-38152 | Med | 0.36 | 5.3 | 0.24 | Sep 12, 2023 | DHCP Server Service Information Disclosure Vulnerability | ||
| CVE-2023-36803 | Med | 0.36 | 5.5 | 0.01 | Sep 12, 2023 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2023-35324 | Med | 0.36 | 5.5 | 0.01 | Jul 11, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2023-32085 | Med | 0.36 | 5.5 | 0.01 | Jul 11, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2023-28266 | Med | 0.36 | 5.5 | 0.04 | Apr 11, 2023 | Windows Common Log File System Driver Information Disclosure Vulnerability |
- risk 0.36cvss 5.5epss 0.01
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
- risk 0.36cvss 5.5epss 0.00
Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.
- risk 0.36cvss 5.5epss 0.01
Windows Resilient File System (ReFS) Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
- risk 0.36cvss 5.5epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Transient DOS while processing channel information for speaker protection v2 module in ADSP.
- risk 0.36cvss 5.5epss 0.00
Transient DOS in Audio when invoking callback function of ASM driver.
- risk 0.36cvss 5.3epss 0.24
DHCP Server Service Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.04
Windows Common Log File System Driver Information Disclosure Vulnerability