CWE-126
476 CVEs • Abstraction: Variant
Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
CVEs (476)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Dec 9, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJun 17, 2026 Dec 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJun 17, 2026 Dec 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJun 17, 2026 Dec 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJun 17, 2026 Dec 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. |
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses |
A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version...Show more |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Nov 11, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. |
A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is re...Show more |
1Qualcomm 8Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSc8380xp Firmware+5 moreJun 17, 2026 Nov 4, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing. |
1Qualcomm 38Msm8996au Firmware Qam8255p FirmwareQam8295p Firmware+35 moreJun 17, 2026 Nov 4, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Information disclosure while processing message from client with invalid payload. |
1Qualcomm 77Fastconnect 6900 Firmware Fastconnect 7800 FirmwareImmersive Home 3210 Platform Firmware+74 moreJun 17, 2026 Nov 4, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Information disclosure while registering commands from clients with diag through diagHal. |
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the correspond...Show more |
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corres...Show more |
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function |
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corr...Show more |
In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with th...Show more |
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when received an Ethernet with type set as IP but...Show more |
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4...Show more |
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field. |