← Back
CWE-126

476 CVEs • Abstraction: Variant

Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

JSON object

Loading...

CVEs (476)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jul 21, 2026
Jul 20, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficie...Show more
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for specific capability sets. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed capability data. Due to missing bounds checks, the xrdp process may perform out-of-bounds memory reads, which can result in the termination of the service (Denial of Service). However, since xrdp forks a new process for each connection by default, an out-of-bounds read causing a process crash is unlikely to bring down the entire xrdp service. This issue has been fixed in version 0.10.6.1.Show less
-
-
Jul 20, 2026
Jul 20, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted f...Show more
ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative off_t value. Attackers can exploit the subsequent conversion to uint32_t, causing an approximately 4 GB requested read length and forcing the server to read beyond the end of the SSH channel data and write overread process memory into the uploaded file. In tested configurations, the disclosed data contains libc, libcrypto, and PIE pointers sufficient to derive their randomized base addresses, thereby bypassing ASLR and enabling reliable exploitation of memory corruption vulnerabilities in the same process.Show less
-
-
Jul 17, 2026
Jul 16, 2026
N/A· v4
3.1 LOW· v3
N/A· v2
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending wit...Show more
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user.Show less
-
-
Jul 15, 2026
Jul 14, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four b...Show more
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.Show less
1Microsoft
1Windows Subsystem For Linux
Jul 20, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
1Microsoft
7365 Apps
ExcelMicrosoft 365+4 more
Jul 16, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 21, 2026
Jul 14, 2026
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
1Microsoft
1Sql Server 2025
Jul 22, 2026
Jul 14, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 23, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
1Microsoft
9Windows 10 1809
Windows 10 21h2Windows 10 22h2+6 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 22, 2026
Jul 14, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jul 20, 2026
Jul 14, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
1Fortinet
2Fortios
Fortiproxy
Jul 16, 2026
Jul 14, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiPr...Show more
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here>Show less
1Fortinet
2Fortios
Fortiproxy
Jul 16, 2026
Jul 14, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attack...Show more
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.Show less
-
-
Jul 9, 2026
Jul 8, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path
1Qualcomm
47Aqt1000 Firmware
Cologne FirmwareFastconnect 6200 Firmware+44 more
Jul 7, 2026
Jul 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.