CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (529)
page 25 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-12975 | Low | 0.07 | — | 0.00 | Mar 7, 2025 | A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface. | ||
| CVE-2023-49285 | Hig | 0.07 | 8.6 | 0.88 | Dec 4, 2023 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no… | ||
| CVE-2026-70652 | Low | 0.06 | — | 0.00 | Aug 20, 2026 | libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming… | ||
| CVE-2025-11961 | Low | 0.05 | 1.9 | 0.00 | Dec 31, 2025 | pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an… | ||
| CVE-2006-7197 | 0.01 | — | 0.08 | Apr 25, 2007 | The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory. | |||
| CVE-2026-62353 | Med | 0.00 | 5.4 | 0.00 | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an… | ||
| CVE-2026-57968 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-55036 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-50504 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-50485 | Med | 0.00 | 4.5 | 0.01 | Jul 14, 2026 | Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | ||
| CVE-2026-50475 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50468 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-50445 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-50435 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50402 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50383 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50372 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50341 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-21379 | Hig | 0.00 | 7.8 | 0.00 | Jul 6, 2026 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. | ||
| CVE-2026-26271 | Med | 0.00 | 5.3 | 0.00 | Feb 25, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data. The bug is reachable over the network… |
- risk 0.07cvss —epss 0.00
A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.
- risk 0.07cvss 8.6epss 0.88
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no…
- risk 0.06cvss —epss 0.00
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming…
- risk 0.05cvss 1.9epss 0.00
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an…
- CVE-2006-7197Apr 25, 2007risk 0.01cvss —epss 0.08
The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.
- risk 0.00cvss 5.4epss 0.00
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an…
- risk 0.00cvss 7.8epss 0.00
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 6.5epss 0.01
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 4.5epss 0.01
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
- risk 0.00cvss 5.5epss 0.00
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.00cvss 6.5epss 0.01
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.00cvss 6.5epss 0.01
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 7.8epss 0.00
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.1epss 0.00
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
- risk 0.00cvss 7.0epss 0.00
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
- risk 0.00cvss 5.3epss 0.00
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data. The bug is reachable over the network…