← Back
CWE-126

476 CVEs • Abstraction: Variant

Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

JSON object

Loading...

CVEs (476)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
192Ar8035 Firmware
Csr8811 FirmwareFastconnect 6200 Firmware+189 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report.
1Qualcomm
319315 5g Iot Modem Firmware
860 Mobile Platform FirmwareApq8064au Firmware+316 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing ESP IE from beacon/probe response frame.
1Qualcomm
169Ar8035 Firmware
Csr8811 FirmwareFastconnect 6700 Firmware+166 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.
1Qualcomm
247Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+244 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
1Qualcomm
247Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+244 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
1Qualcomm
247205 Mobile Platform Firmware
215 Mobile Platform Firmware315 5g Iot Modem Firmware+244 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
1Qualcomm
94Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6800 Firmware+91 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS during music playback of ALAC content.
1Qualcomm
129Csr8811 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+126 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Information disclosure while handling beacon probe frame during scan entry generation in client side.
1Qualcomm
175Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+172 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Information disclosure while handling beacon or probe response frame in STA.
1Microsoft
6Windows Server 2008
Windows Server 2012Windows Server 2016+3 more
Jun 17, 2026
Jul 9, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Jul 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Jul 9, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Windows Remote Access Connection Manager Information Disclosure Vulnerability
1Qualcomm
2579205 Lte Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+254 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing key blob passed by the user.
1Qualcomm
309315 5g Iot Modem Firmware
9205 Lte Modem FirmwareAqt1000 Firmware+306 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Transient DOS while loading the TA ELF file.
1Qualcomm
111Ar8035 Firmware
Csr8811 FirmwareFastconnect 7800 Firmware+108 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Information disclosure while handling SA query action frame.
1Qualcomm
111Ar8035 Firmware
Csr8811 FirmwareFastconnect 7800 Firmware+108 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
INformation disclosure while handling Multi-link IE in beacon frame.
1Qualcomm
42Ar8035 Firmware
Fastconnect 7800 FirmwareQam8255p Firmware+39 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Information Disclosure while parsing beacon frame in STA.
1Amazon
1Freertos Plus Tcp
Jun 17, 2026
Jun 24, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A care...Show more
FreeRTOS-Plus-TCP is a lightweight TCP/IP stack for FreeRTOS. FreeRTOS-Plus-TCP versions 4.0.0 through 4.1.0 contain a buffer over-read issue in the DNS Response Parser when parsing domain names in a DNS response. A carefully crafted DNS response with domain name length value greater than the actual domain name length, could cause the parser to read beyond the DNS response buffer. This issue affects applications using DNS functionality of the FreeRTOS-Plus-TCP stack. Applications that do not use DNS functionality are not affected, even when the DNS functionality is enabled. This vulnerability has been patched in version 4.1.1.Show less
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jul 20, 2026
Jun 11, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Windows Remote Access Connection Manager Information Disclosure Vulnerability
1Qualcomm
124Ar8035 Firmware
Csr8811 FirmwareFastconnect 6900 Firmware+121 more
Jun 17, 2026
Jun 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.