CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (529)
page 22 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-76653 | Med | 0.34 | — | 0.00 | Sep 10, 2026 | A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information… | ||
| CVE-2026-65936 | Med | 0.34 | — | 0.00 | Aug 13, 2026 | A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below. | ||
| CVE-2026-65933 | Med | 0.34 | — | 0.00 | Aug 13, 2026 | A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below. | ||
| CVE-2025-60729 | Med | 0.34 | 5.3 | 0.00 | Oct 24, 2025 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function | ||
| CVE-2025-55093 | Med | 0.34 | 5.3 | 0.00 | Oct 17, 2025 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corruption of 4 bytes of memory. | ||
| CVE-2025-55092 | Med | 0.34 | 5.3 | 0.00 | Oct 17, 2025 | In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with the timestamp option. | ||
| CVE-2025-55084 | Med | 0.34 | 5.3 | 0.00 | Oct 16, 2025 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field. | ||
| CVE-2025-55083 | Med | 0.34 | 5.3 | 0.00 | Oct 15, 2025 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read. | ||
| CVE-2023-45919 | Med | 0.34 | 5.3 | 0.00 | Mar 27, 2024 | Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server. | ||
| CVE-2023-3649 | Med | 0.34 | 5.3 | 0.00 | Jul 14, 2023 | iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file | ||
| CVE-2026-50813 | Med | 0.33 | 6.1 | 0.00 | Jul 8, 2026 | An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path | ||
| CVE-2026-11787 | Med | 0.33 | 5.0 | 0.00 | Jun 9, 2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior. | ||
| CVE-2024-9843 | Med | 0.33 | 5.0 | 0.00 | Nov 12, 2024 | A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service. | ||
| CVE-2023-33078 | Med | 0.33 | 5.1 | 0.00 | Mar 4, 2024 | Information Disclosure while processing IOCTL request in FastRPC. | ||
| CVE-2022-33220 | Med | 0.33 | 5.1 | 0.00 | Sep 5, 2023 | Information disclosure in Automotive multimedia due to buffer over-read. | ||
| CVE-2026-69474 | Med | 0.31 | 4.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-69316 | Med | 0.31 | 4.7 | 0.00 | Sep 8, 2026 | Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. | ||
| CVE-2026-45460 | Med | 0.31 | 4.7 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2024-30071 | Med | 0.31 | 4.7 | 0.01 | Jul 9, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-30069 | Med | 0.31 | 4.7 | 0.01 | Jun 11, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability |
- risk 0.34cvss —epss 0.00
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information…
- risk 0.34cvss —epss 0.00
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
- risk 0.34cvss —epss 0.00
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
- risk 0.34cvss 5.3epss 0.00
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
- risk 0.34cvss 5.3epss 0.00
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corruption of 4 bytes of memory.
- risk 0.34cvss 5.3epss 0.00
In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with the timestamp option.
- risk 0.34cvss 5.3epss 0.00
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field.
- risk 0.34cvss 5.3epss 0.00
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read.
- risk 0.34cvss 5.3epss 0.00
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
- risk 0.34cvss 5.3epss 0.00
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
- risk 0.33cvss 6.1epss 0.00
An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path
- risk 0.33cvss 5.0epss 0.00
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
- risk 0.33cvss 5.0epss 0.00
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
- risk 0.33cvss 5.1epss 0.00
Information Disclosure while processing IOCTL request in FastRPC.
- risk 0.33cvss 5.1epss 0.00
Information disclosure in Automotive multimedia due to buffer over-read.
- risk 0.31cvss 4.8epss 0.01
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.
- risk 0.31cvss 4.7epss 0.00
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
- risk 0.31cvss 4.7epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.31cvss 4.7epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability