CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (492)
page 6 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-49031 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft Office Graphics Remote Code Execution Vulnerability | ||
| CVE-2024-38261 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-38250 | Hig | 0.51 | 7.8 | 0.01 | Sep 10, 2024 | Windows Graphics Component Elevation of Privilege Vulnerability | ||
| CVE-2024-38135 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | ||
| CVE-2024-38127 | Hig | 0.51 | 7.8 | 0.02 | Aug 13, 2024 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2024-30079 | Hig | 0.51 | 7.8 | 0.01 | Jul 9, 2024 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | ||
| CVE-2024-21465 | Hig | 0.51 | 7.8 | 0.00 | Jul 1, 2024 | Memory corruption while processing key blob passed by the user. | ||
| CVE-2023-33115 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2024 | Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. | ||
| CVE-2024-26176 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-20290 | Hig | 0.51 | 7.5 | 0.34 | Feb 7, 2024 | A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may… | ||
| CVE-2023-38144 | Hig | 0.51 | 7.8 | 0.05 | Sep 12, 2023 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-36773 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | 3D Builder Remote Code Execution Vulnerability | ||
| CVE-2023-36904 | Hig | 0.51 | 7.8 | 0.01 | Aug 8, 2023 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-28542 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in WLAN HOST while fetching TX status information. | ||
| CVE-2023-28541 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Memory Corruption in Data Modem while processing DMA buffer release event about CFR data. | ||
| CVE-2020-35511 | Hig | 0.51 | 7.8 | 0.00 | Aug 23, 2022 | A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file. | ||
| CVE-2026-41992 | Hig | 0.49 | 7.5 | 0.00 | Jun 29, 2026 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and… | ||
| CVE-2026-21381 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | ||
| CVE-2026-21367 | Hig | 0.49 | 7.6 | 0.00 | Apr 6, 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | ||
| CVE-2026-20846 | Hig | 0.49 | 7.5 | 0.01 | Feb 10, 2026 | Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. |
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Graphics Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Graphics Component Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing key blob passed by the user.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.5epss 0.34
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may…
- risk 0.51cvss 7.8epss 0.05
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
3D Builder Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in WLAN HOST while fetching TX status information.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
- risk 0.51cvss 7.8epss 0.00
A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.
- risk 0.49cvss 7.5epss 0.00
GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and…
- risk 0.49cvss 7.6epss 0.00
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
- risk 0.49cvss 7.6epss 0.00
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
- risk 0.49cvss 7.5epss 0.01
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.