CWE-126
519 CVEs • Abstraction: Variant
Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
CVEs (519)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 241Ar8035 Firmware Cologne FirmwareCq7790 Firmware+238 moreJun 17, 2026 May 4, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when processing target power rate tables during channel configuration. |
Buffer Over-read vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue. |
1Linuxfoundation 1Automotive Grade Linux Jun 17, 2026 May 1, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_receive (receive.c:87-89), the payload_length for a Single Frame is extracted from a 4-bit nibble in t...Show more |
Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LO...Show more |
1Rust Openssl Project 1Rust Openssl Jul 15, 2026 Apr 24, 2026 8.3 HIGH· v4 5.3 MEDIUM· v3 N/A· v2 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generat...Show more |
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacen...Show more |
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB dev...Show more |
1Microsoft 11Windows 10 1809 Windows 10 21h2Windows 10 22h2+8 moreJun 17, 2026 Apr 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Apr 14, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Apr 14, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard * exhausts the entire ho...Show more |
1Qualcomm 102Ar8035 Firmware Cologne FirmwareFastconnect 6200 Firmware+99 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. |
1Qualcomm 51Aqt1000 Firmware Cologne FirmwareFastconnect 6200 Firmware+48 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. |
1Qualcomm 54Aqt1000 Firmware Cologne FirmwareFastconnect 6200 Firmware+51 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. |
1Qualcomm 35Cologne Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+32 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
1Qualcomm 54Aqt1000 Firmware Cologne FirmwareFastconnect 6200 Firmware+51 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. |
1Qualcomm 54Aqt1000 Firmware Cologne FirmwareFastconnect 6200 Firmware+51 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
1Qualcomm 52Aqt1000 Firmware Cologne FirmwareFastconnect 6200 Firmware+49 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption when retrieving output buffer with insufficient size validation. |
1Qualcomm 149Ar8035 Firmware Cologne FirmwareCsr8811 Firmware+146 moreJun 17, 2026 Apr 6, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. |