CWE-126
476 CVEs • Abstraction: Variant
Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
CVEs (476)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 31Ar8035 Firmware Fastconnect 7800 FirmwareQca6574au Firmware+28 moreJun 17, 2026 May 6, 2025 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Memory corruption while decoding of OTA messages from T3448 IE. |
1Qualcomm 13Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSdm429w Firmware+10 moreJun 17, 2026 May 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption due to improper bounds check while command handling in camera-kernel driver. |
1Microsoft 7Windows Server 2008 Windows Server 2012Windows Server 2016+4 moreJun 17, 2026 Apr 8, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Apr 8, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. |
1Microsoft 7Windows Server 2008 Windows Server 2012Windows Server 2016+4 moreJun 17, 2026 Apr 8, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. |
1Microsoft 7Windows Server 2008 Windows Server 2012Windows Server 2016+4 moreJun 17, 2026 Apr 8, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. |
1Qualcomm 267315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+264 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS may occur while parsing SSID in action frames. |
1Qualcomm 149Ar8035 Firmware Csr8811 FirmwareFastconnect 6800 Firmware+146 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS may occur while parsing extended IE in beacon. |
1Qualcomm 121Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+118 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS may occur while parsing EHT operation IE or EHT capability IE. |
1Qualcomm 223315 5g Iot Modem Firmware Apq8017 FirmwareApq8064au Firmware+220 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. |
1Qualcomm 1839206 Lte Modem Firmware Apq8017 FirmwareApq8064au Firmware+180 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. |
1Qualcomm 699206 Lte Modem Firmware Apq8017 FirmwareAr8031 Firmware+66 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. |
1Qualcomm 45Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+42 moreJun 17, 2026 Apr 7, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing escape code in API. |
1Qualcomm 145Apq8064au Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+142 moreJun 17, 2026 Apr 7, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. |
A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read. |
A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read. |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 21h2+11 moreJun 17, 2026 Mar 11, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. |
A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface. |
1Qualcomm 187Aqt1000 Firmware Ar8035 FirmwareFastconnect 6200 Firmware+184 moreJun 17, 2026 Mar 3, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Transient DOS during hypervisor virtual I/O operation in a virtual machine. |
libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c via a TAR archive because it mishandles truncation in the middle of a GNU long linkname. |