CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (531)
page 26 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-50485 | Med | 0.00 | 4.5 | 0.01 | Jul 14, 2026 | Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | ||
| CVE-2026-50475 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50468 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-50445 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-50435 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50402 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50383 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. | ||
| CVE-2026-50372 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50341 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-21379 | Hig | 0.00 | 7.8 | 0.00 | Jul 6, 2026 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. | ||
| CVE-2026-26271 | Med | 0.00 | 5.3 | 0.00 | Feb 25, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data. The bug is reachable over the network… | ||
| CVE-2025-66692 | Hig | 0.00 | 7.5 | 0.00 | Jan 20, 2026 | A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input. | ||
| CVE-2025-62787 | Hig | 0.00 | 7.5 | 0.00 | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) is incorrect. A compromised agent can… | ||
| CVE-2025-59933 | Hig | 0.00 | 7.8 | 0.00 | Sep 29, 2025 | libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips is compiled with support for PDF input via poppler, the pdfload operation is affected by a buffer read overflow when parsing the header of a crafted PDF with a… | ||
| CVE-2023-51773 | Cri | 0.00 | 9.1 | 0.01 | Feb 29, 2024 | BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c. | ||
| CVE-2023-6936 | Med | 0.00 | 5.3 | 0.01 | Feb 20, 2024 | In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging). | ||
| CVE-2023-4758 | Med | 0.00 | 5.5 | 0.00 | Sep 4, 2023 | Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV. | ||
| CVE-2023-0817 | Hig | 0.00 | 7.8 | 0.00 | Feb 13, 2023 | Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV. | ||
| CVE-2022-3178 | Hig | 0.00 | 7.8 | 0.00 | Sep 12, 2022 | Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV. | ||
| CVE-2022-2301 | Med | 0.00 | 5.5 | 0.01 | Jul 4, 2022 | Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3. |
- risk 0.00cvss 4.5epss 0.01
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
- risk 0.00cvss 5.5epss 0.00
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.00cvss 6.5epss 0.01
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.00cvss 6.5epss 0.01
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 7.8epss 0.00
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.1epss 0.00
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
- risk 0.00cvss 7.0epss 0.00
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.00
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
- risk 0.00cvss 5.3epss 0.00
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data. The bug is reachable over the network…
- risk 0.00cvss 7.5epss 0.00
A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- risk 0.00cvss 7.5epss 0.00
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) is incorrect. A compromised agent can…
- risk 0.00cvss 7.8epss 0.00
libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips is compiled with support for PDF input via poppler, the pdfload operation is affected by a buffer read overflow when parsing the header of a crafted PDF with a…
- risk 0.00cvss 9.1epss 0.01
BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.
- risk 0.00cvss 5.3epss 0.01
In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging).
- risk 0.00cvss 5.5epss 0.00
Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV.
- risk 0.00cvss 7.8epss 0.00
Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.
- risk 0.00cvss 7.8epss 0.00
Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.
- risk 0.00cvss 5.5epss 0.01
Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.