CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (529)
page 18 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28569 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL while handling command through WMI interfaces. | ||
| CVE-2023-28568 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL when reception status handler is called. | ||
| CVE-2023-28566 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL while handling the WMI state info command. | ||
| CVE-2023-28563 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in IOE Firmware while handling WMI command. | ||
| CVE-2023-28554 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. | ||
| CVE-2023-28553 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information Disclosure in WLAN Host when processing WMI event command. | ||
| CVE-2023-28571 | Med | 0.40 | 6.1 | 0.00 | Oct 3, 2023 | Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan. | ||
| CVE-2023-21697 | Med | 0.40 | 6.2 | 0.01 | Feb 14, 2023 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | ||
| CVE-2026-68819 | Med | 0.38 | 5.9 | 0.01 | Aug 11, 2026 | Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-7745 | Med | 0.38 | 5.8 | 0.00 | Jul 24, 2025 | Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2. | ||
| CVE-2025-4207 | Med | 0.38 | 5.9 | 0.01 | May 8, 2025 | Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL… | ||
| CVE-2023-39541 | Med | 0.38 | 5.9 | 0.01 | Feb 20, 2024 | A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This… | ||
| CVE-2023-39540 | Med | 0.38 | 5.9 | 0.01 | Feb 20, 2024 | A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This… | ||
| CVE-2022-23130 | Med | 0.38 | 5.9 | 0.01 | Jan 21, 2022 | Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 and prior, Mitsubishi Electric ICONICS Suite versions 10.97… | ||
| CVE-2026-69416 | Med | 0.37 | 5.7 | 0.01 | Sep 8, 2026 | Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | ||
| CVE-2024-26160 | Med | 0.37 | 5.5 | 0.11 | Mar 12, 2024 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | ||
| CVE-2026-83951 | Med | 0.36 | 5.5 | 0.01 | Sep 8, 2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-83949 | Med | 0.36 | 5.5 | 0.01 | Sep 8, 2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-81399 | Med | 0.36 | 5.5 | 0.01 | Sep 8, 2026 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-69794 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. |
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL while handling command through WMI interfaces.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL when reception status handler is called.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL while handling the WMI state info command.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in IOE Firmware while handling WMI command.
- risk 0.40cvss 6.1epss 0.00
Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.
- risk 0.40cvss 6.1epss 0.00
Information Disclosure in WLAN Host when processing WMI event command.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
- risk 0.40cvss 6.2epss 0.01
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
- risk 0.38cvss 5.9epss 0.01
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
- risk 0.38cvss 5.8epss 0.00
Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
- risk 0.38cvss 5.9epss 0.01
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL…
- risk 0.38cvss 5.9epss 0.01
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…
- risk 0.38cvss 5.9epss 0.01
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This…
- risk 0.38cvss 5.9epss 0.01
Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 and prior, Mitsubishi Electric ICONICS Suite versions 10.97…
- risk 0.37cvss 5.7epss 0.01
Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
- risk 0.37cvss 5.5epss 0.11
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.