VYPR

CWE-126

Buffer Over-read

VariantDraft

Description

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (492)

page 20 of 25
  • CVE-2021-34303MedJul 13, 2021
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds…

  • CVE-2021-34302MedJul 13, 2021
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. This could result in an out of bounds…

  • CVE-2021-34299MedJul 13, 2021
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds…

  • CVE-2026-55970MedJul 27, 2026
    risk 0.35cvss 6.5epss 0.01

    Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

  • CVE-2026-63091MedJul 20, 2026
    risk 0.35cvss 6.5epss 0.00

    ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative…

  • CVE-2026-58013MedJun 30, 2026
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor…

  • CVE-2026-58012MedJun 30, 2026
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8…

  • CVE-2026-58010MedJun 30, 2026
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can…

  • CVE-2026-24028MedMar 31, 2026
    risk 0.35cvss 5.3epss 0.01

    An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory,…

  • CVE-2025-11617MedOct 10, 2025
    risk 0.35cvss 5.4epss 0.00

    A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6. We recommend users upgrade to the…

  • CVE-2025-11616MedOct 10, 2025
    risk 0.35cvss 5.4epss 0.00

    A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect applications using IPv6. Users should…

  • CVE-2025-29956MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.01

    Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.

  • CVE-2023-36801MedSep 12, 2023
    risk 0.35cvss 5.3epss 0.01

    DHCP Server Service Information Disclosure Vulnerability

  • CVE-2023-21720MedFeb 14, 2023
    risk 0.35cvss 5.3epss 0.01

    Microsoft Edge (Chromium-based) Tampering Vulnerability

  • CVE-2021-1614MedJul 22, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory. This vulnerability is due to insufficient handling of…

  • CVE-2020-8244MedAug 30, 2020
    risk 0.35cvss 6.5epss 0.02

    A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing…

  • CVE-2025-60729MedOct 24, 2025
    risk 0.34cvss 5.3epss 0.00

    PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function

  • CVE-2025-55093MedOct 17, 2025
    risk 0.34cvss 5.3epss 0.00

    In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corruption of 4 bytes of memory.

  • CVE-2025-55092MedOct 17, 2025
    risk 0.34cvss 5.3epss 0.00

    In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with the timestamp option.

  • CVE-2025-55084MedOct 16, 2025
    risk 0.34cvss 5.3epss 0.00

    In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field.