CWE-126
Buffer Over-read
Description
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Hierarchy (View 1000)
CVEs mapped to this weakness (529)
page 8 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-52877 | Hig | 0.49 | 7.5 | 0.00 | May 15, 2025 | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In… | ||
| CVE-2025-21459 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2025 | Transient DOS while parsing per STA profile in ML IE. | ||
| CVE-2024-49847 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2025 | Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE. | ||
| CVE-2025-21448 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. | ||
| CVE-2025-21435 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing extended IE in beacon. | ||
| CVE-2025-21434 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing EHT operation IE or EHT capability IE. | ||
| CVE-2025-21430 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | ||
| CVE-2025-21429 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. | ||
| CVE-2025-21428 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. | ||
| CVE-2024-12011 | Hig | 0.49 | 7.6 | 0.00 | Feb 13, 2025 | A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The information disclosure can be triggered by leveraging a memory leak affecting the web server. A remote unauthenticated attacker can exploit this vulnerability… | ||
| CVE-2024-38404 | Hig | 0.49 | 7.5 | 0.00 | Feb 3, 2025 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem. | ||
| CVE-2024-45558 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2025 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | ||
| CVE-2024-38405 | Hig | 0.49 | 7.5 | 0.00 | Nov 4, 2024 | Transient DOS while processing the CU information from RNR IE. | ||
| CVE-2024-38403 | Hig | 0.49 | 7.5 | 0.00 | Nov 4, 2024 | Transient DOS while parsing BTM ML IE when per STA profile is not included. | ||
| CVE-2024-38397 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS while parsing probe response and assoc response frame. | ||
| CVE-2024-33071 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0. | ||
| CVE-2024-33070 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. | ||
| CVE-2024-33049 | Hig | 0.49 | 7.5 | 0.00 | Oct 7, 2024 | Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame. | ||
| CVE-2024-9029 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2024 | A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in the Source/Metadata/IPTC.cpp file because the size of the profile is not being sanitized, causing a crash in the application linked… | ||
| CVE-2024-33057 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. |
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In…
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing per STA profile in ML IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing SSID in action frames.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing extended IE in beacon.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- risk 0.49cvss 7.5epss 0.00
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
- risk 0.49cvss 7.5epss 0.00
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
- risk 0.49cvss 7.6epss 0.00
A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The information disclosure can be triggered by leveraging a memory leak affecting the web server. A remote unauthenticated attacker can exploit this vulnerability…
- risk 0.49cvss 7.5epss 0.00
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.
- risk 0.49cvss 7.5epss 0.00
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing the CU information from RNR IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing BTM ML IE when per STA profile is not included.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing probe response and assoc response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ESP IE from beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
- risk 0.49cvss 7.5epss 0.01
A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in the Source/Metadata/IPTC.cpp file because the size of the profile is not being sanitized, causing a crash in the application linked…
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.