CWE-126
519 CVEs • Abstraction: Variant
Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
CVEs (519)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 11Pandeiro Firmware Snapdragon 8 Elite Gen 5 FirmwareSw6100 Firmware+8 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 Cryptographic issue while copying data to a destination buffer without validating its size. |
1Qualcomm 29Cologne Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+26 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while preprocessing IOCTL request in JPEG driver. |
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34,...Show more |
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leadi...Show more |
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and val...Show more |
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause...Show more |
1Qualcomm 162Ar8031 Firmware Ar8035 FirmwareCsra6620 Firmware+159 moreJun 17, 2026 Mar 2, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption when adding user-supplied data without checking available buffer space. |
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds...Show more |
2Dlemstra Imagemagick2Imagemagick Magick.netJun 17, 2026 Feb 26, 2026 N/A· v4 4.4 MEDIUM· v3 N/A· v2 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The...Show more |
2Dlemstra Imagemagick2Imagemagick Magick.netJun 17, 2026 Feb 26, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small di...Show more |
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon...Show more |
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service |
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Openin...Show more |
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quant...Show more |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreAug 19, 2026 Feb 10, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. |
1Qualcomm 94Ar8035 Firmware Cologne FirmwareFastconnect 6900 Firmware+91 moreJun 17, 2026 Feb 2, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Transient DOS when processing a received frame with an excessively large authentication information element. |
A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input. |
A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affec...Show more |
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element. |
1Qualcomm 297Ar8031 Firmware Ar8035 FirmwareCsr8811 Firmware+294 moreJun 17, 2026 Jan 7, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Information disclosure while processing a firmware event. |