← Back
CWE-126

519 CVEs • Abstraction: Variant

Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

JSON object

Loading...

CVEs (519)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
1Thunderbird
Sep 3, 2026
Sep 1, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
-
-
Aug 21, 2026
Aug 20, 2026
2.0 LOW· v4
N/A· v3
N/A· v2
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_sa...Show more
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.Show less
-
-
Sep 9, 2026
Aug 20, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixe...Show more
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.Show less
1Wireshark
1Wireshark
Aug 31, 2026
Aug 19, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
1Wireshark
1Wireshark
Aug 31, 2026
Aug 19, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
1Microsoft
1Windows App
Aug 27, 2026
Aug 19, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
-
-
Sep 8, 2026
Aug 13, 2026
5.3 MEDIUM· v4
N/A· v3
N/A· v2
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.  See vulnerability B-E4 in the related paper below.
-
-
Sep 8, 2026
Aug 13, 2026
5.3 MEDIUM· v4
N/A· v3
N/A· v2
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
1Postgresql
1Postgresql
Aug 29, 2026
Aug 13, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, th...Show more
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.Show less
1Postgresql
1Postgresql
Aug 29, 2026
Aug 13, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions...Show more
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.Show less
1Microsoft
7Windows 10 1607
Windows 10 1809Windows Server 2012+4 more
Aug 16, 2026
Aug 11, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Aug 16, 2026
Aug 11, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
1Microsoft
6365 Apps
Microsoft 365Office 2019+3 more
Aug 14, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Aug 16, 2026
Aug 11, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Aug 16, 2026
Aug 11, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Aug 16, 2026
Aug 11, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Aug 16, 2026
Aug 11, 2026
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Aug 16, 2026
Aug 11, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
-
-
Aug 28, 2026
Aug 11, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
-
-
Aug 6, 2026
Aug 5, 2026
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This...Show more
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.Show less