← Back
CWE-126

476 CVEs • Abstraction: Variant

Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

JSON object

Loading...

CVEs (476)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
180315 5g Iot Firmware
Apq8017 FirmwareApq8064au Firmware+177 more
Jun 17, 2026
Jul 8, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS may occur while processing malformed length field in SSID IEs.
1Qualcomm
235Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+232 more
Jun 17, 2026
Jul 8, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
1Qualcomm
173205 Mobile Firmware
215 Mobile FirmwareApq8064au Firmware+170 more
Jun 17, 2026
Jul 8, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Jun 10, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
1Qualcomm
67Fastconnect 7800 Firmware
Immersive Home 3210 Platform FirmwareImmersive Home 326 Platform Firmware+64 more
Jun 17, 2026
Jun 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.
1Qualcomm
210Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+207 more
Jun 17, 2026
Jun 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while processing the EHT operation IE in the received beacon frame.
1Qualcomm
232205 Mobile Platform Firmware
215 Mobile Platform FirmwareApq8017 Firmware+229 more
Jun 17, 2026
Jun 3, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
1Qualcomm
223205 Mobile Platform Firmware
215 Mobile Platform FirmwareApq8017 Firmware+220 more
Jun 17, 2026
Jun 3, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Information disclosure may occur while processing goodbye RTCP packet from network.
1Qualcomm
232205 Mobile Platform Firmware
215 Mobile Platform FirmwareApq8017 Firmware+229 more
Jun 17, 2026
Jun 3, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
1Qualcomm
79Fastconnect 6200 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+76 more
Jun 17, 2026
Jun 3, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.
1Fortinet
1Fortios
Jun 17, 2026
May 28, 2025
N/A· v4
3.7 LOW· v3
N/A· v2
A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially cr...Show more
A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.Show less
1Insyde
1Insydeh2o
Jun 17, 2026
May 15, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61....Show more
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read.Show less
1Insyde
1Insydeh2o
Jun 17, 2026
May 15, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61....Show more
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, VariableServicesSetVariable () can be called by gRT_>SetVariable () or the SmmSetSensitiveVariable () or SmmInternalSetVariable () from SMM. In VariableServicesSetVariable (), it uses StrSize () to get variable name size, uses StrLen () to get variable name length and uses StrCmp () to compare strings. These actions may cause a buffer over-read.Show less
1Insyde
1Insydeh2o
Jun 17, 2026
May 15, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61....Show more
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, callback function SmmCreateVariableLockList () calls CreateVariableLockListInSmm (). In CreateVariableLockListInSmm (), it uses StrSize () to get variable name size and it could lead to a buffer over-read.Show less
1Microsoft
4365 Apps
ExcelOffice+1 more
Jun 17, 2026
May 13, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
May 13, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
-
-
Jun 17, 2026
May 8, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the d...Show more
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.Show less
1Qualcomm
40Aqt1000 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+37 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
1Qualcomm
123Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+120 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing per STA profile in ML IE.
1Qualcomm
47Ar8035 Firmware
Fastconnect 7800 FirmwareQca6574au Firmware+44 more
Jun 17, 2026
May 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.