← Back
CWE-126

476 CVEs • Abstraction: Variant

Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

JSON object

Loading...

CVEs (476)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
51Ar8035 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+48 more
Jun 17, 2026
Mar 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Transient DOS while processing channel information for speaker protection v2 module in ADSP.
1Qualcomm
13Fastconnect 6700 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+10 more
Jun 17, 2026
Mar 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information Disclosure while processing IOCTL request in FastRPC.
1Bacnetstack
1Bacnet Stack
Jun 17, 2026
Feb 29, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.
1Wolfssl
1Wolfssl
Jun 17, 2026
Feb 20, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is o...Show more
In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging). Show less
1Weston Embedded
1Uc Tcp Ip
Jun 17, 2026
Feb 20, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a ma...Show more
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv6 ICMPv6 packet.Show less
1Weston Embedded
1Uc Tcp Ip
Jun 17, 2026
Feb 20, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a ma...Show more
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv4 ICMP packet.Show less
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Feb 13, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Windows Kernel Information Disclosure Vulnerability
2Cisco
Fedoraproject
3Fedora
Secure EndpointSecure Endpoint Private Cloud
Jun 17, 2026
Feb 7, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect ch...Show more
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .Show less
1Qualcomm
303315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+300 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parse fils IE with length equal to 1.
1Qualcomm
232315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+229 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
1Qualcomm
101Aqt1000 Firmware
Ar8035 FirmwareC V2x 9150 Firmware+98 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Information disclosure in Audio while accessing AVCS services from ADSP payload.
1Qualcomm
88Aqt1000 Firmware
Ar8035 FirmwareC V2x 9150 Firmware+85 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Transient DOS in Audio when invoking callback function of ASM driver.
1Qualcomm
45Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+42 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
1Qualcomm
45Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+42 more
Jun 17, 2026
Feb 6, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Information disclosure in Modem while processing SIB5.
1Cloudflare
1Zlib
Jun 17, 2026
Jan 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based bu...Show more
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software. Patches: The issue has been patched in commit 8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected. Show less
1Qualcomm
1Qcn7606 Firmware
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual size of the services buffer.
1Qualcomm
102Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+99 more
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.
1Qualcomm
122Ar8035 Firmware
Csra6620 FirmwareCsra6640 Firmware+119 more
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element.
1Qualcomm
284315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+281 more
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in WLAN Firmware while parsing a BTM request.
1Qualcomm
139315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8035 Firmware+136 more
Jun 17, 2026
Jan 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS in Data Modem during DTLS handshake.