VYPR

CWE-126

Buffer Over-read

VariantDraft

Description

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (492)

page 8 of 25
  • CVE-2025-21430HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.

  • CVE-2025-21429HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.

  • CVE-2025-21428HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.

  • CVE-2024-12011HigFeb 13, 2025
    risk 0.49cvss 7.6epss 0.00

    A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The information disclosure can be triggered by leveraging a memory leak affecting the web server. A remote unauthenticated attacker can exploit this vulnerability…

  • CVE-2024-38404HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.

  • CVE-2024-45558HigJan 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.

  • CVE-2024-38405HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing the CU information from RNR IE.

  • CVE-2024-38403HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing BTM ML IE when per STA profile is not included.

  • CVE-2024-38397HigOct 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing probe response and assoc response frame.

  • CVE-2024-33071HigOct 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.

  • CVE-2024-33070HigOct 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing ESP IE from beacon/probe response frame.

  • CVE-2024-33049HigOct 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.

  • CVE-2024-9029HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in the Source/Metadata/IPTC.cpp file because the size of the profile is not being sanitized, causing a crash in the application linked…

  • CVE-2024-33057HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.

  • CVE-2024-33051HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

  • CVE-2024-33050HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.

  • CVE-2024-33048HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

  • CVE-2024-23364HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).

  • CVE-2024-23358HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

  • CVE-2024-33026HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.