← Back
CWE-126

476 CVEs • Abstraction: Variant

Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

JSON object

Loading...

CVEs (476)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wireshark
1Wireshark
Jun 17, 2026
Apr 30, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
1Gnu
1Glibc
Jul 14, 2026
Apr 28, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LO...Show more
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.Show less
1Rust Openssl Project
1Rust Openssl
Jul 15, 2026
Apr 24, 2026
8.3 HIGH· v4
5.3 MEDIUM· v3
N/A· v2
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generat...Show more
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in 0.10.78.Show less
1Wolfssh
1Wolfssh
Jun 17, 2026
Apr 20, 2026
2.3 LOW· v4
4.3 MEDIUM· v3
N/A· v2
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacen...Show more
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacent stack memory to the pseudo-console output.Show less
-
-
Jun 17, 2026
Apr 18, 2026
N/A· v4
3.5 LOW· v3
N/A· v2
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB dev...Show more
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f9329526be5158985987 contains a patch. No known workarounds are available.Show less
1Microsoft
11Windows 10 1809
Windows 10 21h2Windows 10 22h2+8 more
Jun 17, 2026
Apr 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Jun 17, 2026
Apr 14, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Jun 17, 2026
Apr 14, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
1Wolfssl
1Wolfssl
Jun 17, 2026
Apr 9, 2026
2.1 LOW· v4
5.3 MEDIUM· v3
N/A· v2
A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard * exhausts the entire ho...Show more
A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard * exhausts the entire hostname string, the function reads one byte past the buffer without a bounds check, which could cause a crash.Show less
1Qualcomm
102Ar8035 Firmware
Cologne FirmwareFastconnect 6200 Firmware+99 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
1Qualcomm
51Aqt1000 Firmware
Cologne FirmwareFastconnect 6200 Firmware+48 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
1Qualcomm
54Aqt1000 Firmware
Cologne FirmwareFastconnect 6200 Firmware+51 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
1Qualcomm
35Cologne Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+32 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
1Qualcomm
54Aqt1000 Firmware
Cologne FirmwareFastconnect 6200 Firmware+51 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
1Qualcomm
54Aqt1000 Firmware
Cologne FirmwareFastconnect 6200 Firmware+51 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
1Qualcomm
52Aqt1000 Firmware
Cologne FirmwareFastconnect 6200 Firmware+49 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption when retrieving output buffer with insufficient size validation.
1Qualcomm
149Ar8035 Firmware
Cologne FirmwareCsr8811 Firmware+146 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
1Qualcomm
11Pandeiro Firmware
Snapdragon 8 Elite Gen 5 FirmwareSw6100 Firmware+8 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Cryptographic issue while copying data to a destination buffer without validating its size.
1Qualcomm
29Cologne Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+26 more
Jun 17, 2026
Apr 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while preprocessing IOCTL request in JPEG driver.
1Rti
1Connext Professional
Jun 17, 2026
Apr 1, 2026
6.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34,...Show more
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.Show less