CWE-126
476 CVEs • Abstraction: Variant
Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
CVEs (476)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 51Ar8035 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+48 moreJun 17, 2026 Mar 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS while processing channel information for speaker protection v2 module in ADSP. |
1Qualcomm 13Fastconnect 6700 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+10 moreJun 17, 2026 Mar 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information Disclosure while processing IOCTL request in FastRPC. |
BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c. |
In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is o...Show more |
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a ma...Show more |
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a ma...Show more |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Feb 13, 2024 N/A· v4 4.6 MEDIUM· v3 N/A· v2 Windows Kernel Information Disclosure Vulnerability |
2Cisco Fedoraproject3Fedora Secure EndpointSecure Endpoint Private CloudJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect ch...Show more |
1Qualcomm 303315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+300 moreJun 17, 2026 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parse fils IE with length equal to 1. |
1Qualcomm 232315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+229 moreJun 17, 2026 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |
1Qualcomm 101Aqt1000 Firmware Ar8035 FirmwareC V2x 9150 Firmware+98 moreJun 17, 2026 Feb 6, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 Information disclosure in Audio while accessing AVCS services from ADSP payload. |
1Qualcomm 88Aqt1000 Firmware Ar8035 FirmwareC V2x 9150 Firmware+85 moreJun 17, 2026 Feb 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS in Audio when invoking callback function of ASM driver. |
1Qualcomm 45Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+42 moreJun 17, 2026 Feb 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS in Core when DDR memory check is called while DDR is not initialized. |
1Qualcomm 45Ar8035 Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+42 moreJun 17, 2026 Feb 6, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Information disclosure in Modem while processing SIB5. |
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based bu...Show more |
Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual size of the services buffer. |
1Qualcomm 102Ar8035 Firmware Ar9380 FirmwareCsr8811 Firmware+99 moreJun 17, 2026 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver. |
1Qualcomm 122Ar8035 Firmware Csra6620 FirmwareCsra6640 Firmware+119 moreJun 17, 2026 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element. |
1Qualcomm 284315 5g Iot Modem Firmware Aqt1000 FirmwareAr8031 Firmware+281 moreJun 17, 2026 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Firmware while parsing a BTM request. |
1Qualcomm 139315 5g Iot Modem Firmware Aqt1000 FirmwareAr8035 Firmware+136 moreJun 17, 2026 Jan 2, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in Data Modem during DTLS handshake. |