← Back
CWE-126

476 CVEs • Abstraction: Variant

Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

JSON object

Loading...

CVEs (476)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Ios Xe
Jun 17, 2026
Sep 24, 2020
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote a...Show more
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insufficient input validation during CAPWAP packet processing. An attacker could exploit this vulnerability by sending a crafted CAPWAP packet to an affected device, resulting in a buffer over-read. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.Show less
2Bufferlist Project
Debian
2Bufferlist
Debian Linux
Jun 17, 2026
Aug 30, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the Buffe...Show more
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.Show less
1Tcpdump
1Tcpdump
Jun 17, 2026
Jul 22, 2019
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function nam...Show more
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.Show less
1Mqtt Packet Project
1Mqtt Packet
Jun 17, 2026
May 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Jun 17, 2026
May 3, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to in...Show more
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.Show less
1Facebook
1Wangle
Jun 17, 2026
Apr 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00
2Debian
Rdesktop
2Debian Linux
Rdesktop
Jun 17, 2026
Feb 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).
2Debian
Rdesktop
2Debian Linux
Rdesktop
Jun 17, 2026
Feb 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak.
2Debian
Rdesktop
2Debian Linux
Rdesktop
Jun 17, 2026
Feb 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (segfault).
2Debian
Rdesktop
2Debian Linux
Rdesktop
Jun 17, 2026
Feb 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that results in a Denial of Service (segfault).
2Debian
Rdesktop
2Debian Linux
Rdesktop
Jun 17, 2026
Feb 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak.
3Canonical
DebianFreerdp
3Debian Linux
FreerdpUbuntu Linux
Jun 17, 2026
Nov 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).
1Fujielectric
1Frenic Loader 3.3 Firmware
Nov 21, 2024
Oct 1, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on the device.
1Apache
1Http Server
May 13, 2026
Jun 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
6Apache
AppleDebian+3 more
13Clustered Data Ontap
Debian LinuxEnterprise Linux Desktop+10 more
May 13, 2026
Jun 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence...Show more
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.Show less
1Microsoft
3Visual C#
Visual StudioVisual Studio .net
May 27, 2026
Jul 29, 2009
N/A· v4
6.5 MEDIUM· v3
7.8 HIGH· v2
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which...Show more
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."Show less