← Back
CWE-126

476 CVEs • Abstraction: Variant

Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

JSON object

Loading...

CVEs (476)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freeimage Project
1Freeimage
Jun 17, 2026
Sep 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in the Source/Metadata/IPTC.cpp file because the size of the profile is not b...Show more
A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in the Source/Metadata/IPTC.cpp file because the size of the profile is not being sanitized, causing a crash in the application linked to the library, resulting in a denial of service.Show less
1Microsoft
1Windows Server 2008
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Microsoft Windows Admin Center Information Disclosure Vulnerability
1Microsoft
17365 Copilot
OfficeOffice Long Term Servicing Channel+14 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Graphics Component Elevation of Privilege Vulnerability
1Qualcomm
170Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+167 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
1Qualcomm
282315 5g Iot Firmware
9206 Lte FirmwareApq8017 Firmware+279 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
1Qualcomm
252Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+249 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
1Qualcomm
187Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+184 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
1Qualcomm
24Fastconnect 6700 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+21 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when the captureRead QDCM command is invoked from user-space.
1Qualcomm
197205 Mobile Platform Firmware
215 Mobile Platform FirmwareApq8017 Firmware+194 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
1Qualcomm
177Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6700 Firmware+174 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
1Qualcomm
159205 Mobile Platform Firmware
315 5g Iot Modem Firmware9205 Lte Modem Firmware+156 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
1Qualcomm
53205 Mobile Platform Firmware
Apq8017 FirmwareApq8037 Firmware+50 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
1F5
2Nginx Open Source
Nginx Plus
Jun 17, 2026
Aug 14, 2024
5.7 MEDIUM· v4
4.7 MEDIUM· v3
N/A· v2
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue...Show more
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1Microsoft
4Windows 11 22h2
Windows 11 23h2Windows 11 24h2+1 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Hyper-V Elevation of Privilege Vulnerability
1Qualcomm
164Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+161 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
1Qualcomm
167Csr8811 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+164 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
1Qualcomm
96Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6800 Firmware+93 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while processing TID-to-link mapping IE elements.
1Qualcomm
148Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+145 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the received TID-to-link mapping action frame.
1Qualcomm
150Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+147 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.