VYPR

CWE-126

Buffer Over-read

VariantDraft

Description

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (529)

page 25 of 27
  • CVE-2024-12975LowMar 7, 2025
    risk 0.07cvss —epss 0.00

    A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.

  • CVE-2023-49285HigDec 4, 2023
    risk 0.07cvss 8.6epss 0.88

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no…

  • CVE-2026-70652LowAug 20, 2026
    risk 0.06cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming…

  • CVE-2025-11961LowDec 31, 2025
    risk 0.05cvss 1.9epss 0.00

    pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an…

  • CVE-2006-7197Apr 25, 2007
    risk 0.01cvss —epss 0.08

    The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

  • CVE-2026-62353MedJul 15, 2026
    risk 0.00cvss 5.4epss 0.00

    TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string literal such as 'abc\ and read one byte beyond the null terminator, allowing an…

  • CVE-2026-57968HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55036HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-50504MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-50485MedJul 14, 2026
    risk 0.00cvss 4.5epss 0.01

    Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

  • CVE-2026-50475MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-50468MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

  • CVE-2026-50445MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-50435HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50402HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50383MedJul 14, 2026
    risk 0.00cvss 6.1epss 0.00

    Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

  • CVE-2026-50372HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50341MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

  • CVE-2026-21379HigJul 6, 2026
    risk 0.00cvss 7.8epss 0.00

    Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.

  • CVE-2026-26271MedFeb 25, 2026
    risk 0.00cvss 5.3epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data. The bug is reachable over the network…