CWE-126
476 CVEs • Abstraction: Variant
Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
CVEs (476)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 323205 Mobile Platform Firmware 315 5g Iot Modem Firmware9205 Lte Modem Firmware+320 moreJun 17, 2026 Dec 2, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
1Qualcomm 50C V2x 9150 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+47 moreJun 17, 2026 Dec 2, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. |
The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read in src/libs/zbxmedia/email.c |
1Qualcomm 23Mdm9206 Firmware Mdm9607 FirmwareMdm9640 Firmware+20 moreJun 17, 2026 Nov 26, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat' |
1Qualcomm 7Sd 450 Firmware Sd 625 FirmwareSd 820 Firmware+4 moreJan 9, 2025 Nov 26, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation. |
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Nov 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Office Graphics Remote Code Execution Vulnerability |
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service. |
1Qualcomm 98Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+95 moreJun 17, 2026 Nov 4, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Transient DOS while processing the CU information from RNR IE. |
1Qualcomm 77Ar8035 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+74 moreJun 17, 2026 Nov 4, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Transient DOS while parsing BTM ML IE when per STA profile is not included. |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
1Microsoft 4Windows 11 22h2 Windows 11 23h2Windows 11 24h2+1 moreJun 17, 2026 Oct 8, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Resilient File System (ReFS) Information Disclosure Vulnerability |
1Microsoft 6Windows Server 2008 Windows Server 2012Windows Server 2016+3 moreJun 17, 2026 Oct 8, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
1Microsoft 6Windows Server 2008 Windows Server 2012Windows Server 2016+3 moreJun 17, 2026 Oct 8, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
1Qualcomm 115Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+112 moreJun 17, 2026 Oct 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing probe response and assoc response frame. |
1Qualcomm 158Ar8035 Firmware Csr8811 FirmwareFastconnect 6700 Firmware+155 moreJun 17, 2026 Oct 7, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. |
1Qualcomm 5Mdm9628 Firmware Qca6564a FirmwareQca6564au Firmware+2 moreJun 17, 2026 Oct 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0. |
1Qualcomm 5Mdm9628 Firmware Qca6564a FirmwareQca6564au Firmware+2 moreJun 17, 2026 Oct 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing ESP IE from beacon/probe response frame. |
1Qualcomm 5Mdm9628 Firmware Qca6564a FirmwareQca6564au Firmware+2 moreJun 17, 2026 Oct 7, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 Information disclosure while parsing the multiple MBSSID IEs from the beacon. |
1Qualcomm 131Csr8811 Firmware Fastconnect 6700 FirmwareFastconnect 7800 Firmware+128 moreJun 17, 2026 Oct 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame. |