CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (492)
page 5 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-62464 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2025 | Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-62462 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2025 | Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-62461 | Hig | 0.51 | 7.8 | 0.00 | Dec 9, 2025 | Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-60720 | Hig | 0.51 | 7.8 | 0.00 | Nov 11, 2025 | Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-47368 | Hig | 0.51 | 7.8 | 0.00 | Nov 4, 2025 | Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing. | ||
| CVE-2025-59192 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2025 | Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-47317 | Hig | 0.51 | 7.8 | 0.00 | Sep 24, 2025 | Memory corruption due to global buffer overflow when a test command uses an invalid payload type. | ||
| CVE-2025-27068 | Hig | 0.51 | 7.8 | 0.00 | Aug 6, 2025 | Memory corruption while processing an IOCTL command with an arbitrary address. | ||
| CVE-2025-49659 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-47973 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-47971 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-27055 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Memory corruption during the image encoding process. | ||
| CVE-2025-21475 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing escape code, when DisplayId is passed with large unsigned value. | ||
| CVE-2025-21421 | Hig | 0.51 | 7.8 | 0.00 | Apr 7, 2025 | Memory corruption while processing escape code in API. | ||
| CVE-2024-45561 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption while handling IOCTL call from user-space to set latency level. | ||
| CVE-2025-21271 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-45548 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call. | ||
| CVE-2024-45546 | Hig | 0.51 | 7.8 | 0.00 | Jan 6, 2025 | Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space. | ||
| CVE-2024-49088 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-11596 | Hig | 0.51 | 7.8 | 0.00 | Nov 21, 2024 | ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file |
- risk 0.51cvss 7.8epss 0.00
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing.
- risk 0.51cvss 7.8epss 0.00
Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing an IOCTL command with an arbitrary address.
- risk 0.51cvss 7.8epss 0.00
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the image encoding process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing escape code in API.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while handling IOCTL call from user-space to set latency level.
- risk 0.51cvss 7.8epss 0.01
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.
- risk 0.51cvss 7.8epss 0.01
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file