CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (492)
page 21 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55083 | Med | 0.34 | 5.3 | 0.00 | Oct 15, 2025 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read. | ||
| CVE-2023-45919 | Med | 0.34 | 5.3 | 0.00 | Mar 27, 2024 | Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server. | ||
| CVE-2023-3649 | Med | 0.34 | 5.3 | 0.00 | Jul 14, 2023 | iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file | ||
| CVE-2026-50813 | Med | 0.33 | 6.1 | 0.00 | Jul 8, 2026 | An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path | ||
| CVE-2026-11787 | Med | 0.33 | 5.0 | 0.00 | Jun 9, 2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior. | ||
| CVE-2024-9843 | Med | 0.33 | 5.0 | 0.00 | Nov 12, 2024 | A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service. | ||
| CVE-2023-33078 | Med | 0.33 | 5.1 | 0.00 | Mar 4, 2024 | Information Disclosure while processing IOCTL request in FastRPC. | ||
| CVE-2022-33220 | Med | 0.33 | 5.1 | 0.00 | Sep 5, 2023 | Information disclosure in Automotive multimedia due to buffer over-read. | ||
| CVE-2026-45460 | Med | 0.31 | 4.7 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2024-30071 | Med | 0.31 | 4.7 | 0.01 | Jul 9, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-30069 | Med | 0.31 | 4.7 | 0.01 | Jun 11, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2026-61350 | Med | 0.30 | 4.6 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | ||
| CVE-2024-21340 | Med | 0.30 | 4.6 | 0.01 | Feb 13, 2024 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2026-6532 | Med | 0.29 | 5.5 | 0.00 | Apr 30, 2026 | Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service | ||
| CVE-2023-43574 | Med | 0.29 | 4.4 | 0.00 | Nov 8, 2023 | A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information. | ||
| CVE-2023-43572 | Med | 0.29 | 4.4 | 0.00 | Nov 8, 2023 | A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information. | ||
| CVE-2023-43568 | Med | 0.29 | 4.4 | 0.00 | Nov 8, 2023 | A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information. | ||
| CVE-2026-59840 | Med | 0.28 | 4.3 | 0.00 | Jul 14, 2026 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions,… | ||
| CVE-2025-43892 | Med | 0.28 | 4.3 | 0.00 | Jul 14, 2026 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect… | ||
| CVE-2026-6575 | Med | 0.28 | 4.3 | 0.00 | May 14, 2026 | Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor… |
- risk 0.34cvss 5.3epss 0.00
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read.
- risk 0.34cvss 5.3epss 0.00
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
- risk 0.34cvss 5.3epss 0.00
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
- risk 0.33cvss 6.1epss 0.00
An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path
- risk 0.33cvss 5.0epss 0.00
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
- risk 0.33cvss 5.0epss 0.00
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
- risk 0.33cvss 5.1epss 0.00
Information Disclosure while processing IOCTL request in FastRPC.
- risk 0.33cvss 5.1epss 0.00
Information disclosure in Automotive multimedia due to buffer over-read.
- risk 0.31cvss 4.7epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.31cvss 4.7epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.30cvss 4.6epss 0.00
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.30cvss 4.6epss 0.01
Windows Kernel Information Disclosure Vulnerability
- risk 0.29cvss 5.5epss 0.00
Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
- risk 0.29cvss 4.4epss 0.00
A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
- risk 0.29cvss 4.4epss 0.00
A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
- risk 0.29cvss 4.4epss 0.00
A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
- risk 0.28cvss 4.3epss 0.00
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions,…
- risk 0.28cvss 4.3epss 0.00
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect…
- risk 0.28cvss 4.3epss 0.00
Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor…