CWE-126— Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.— MITRE CWE catalog
529 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-126page 9 of 11
- CVE-2025-60003HIGHCVSS 7.5EG 7.52026-01-15
A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When an affected device receives…
- CVE-2025-60720HIGHCVSS 7.8EG 7.82025-11-11
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
- CVE-2025-60729MEDIUMCVSS 5.3EG 5.32025-10-24
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
- CVE-2025-62461HIGHCVSS 7.8EG 7.82025-12-09
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-62462HIGHCVSS 7.8EG 7.82025-12-09
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- CVE-2025-62464HIGHCVSS 7.8EG 7.82025-12-09
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- CVE-2025-62467HIGHCVSS 7.8EG 7.82025-12-09
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- CVE-2025-62473MEDIUMCVSS 6.5EG 6.52025-12-09
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-62560HIGHCVSS 7.8EG 7.82025-12-09
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-62787HIGHCVSS 7.5EG 7.52025-10-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) i…
- CVE-2025-62792HIGHCVSS 7.5EG 7.52025-10-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not b…
- CVE-2025-63602HIGHCVSS 7.3EG 7.32025-11-18
A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0…
- CVE-2025-66038MEDIUMCVSS 6.8EG 6.82026-03-30
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length (low nibb…
- CVE-2025-66692HIGHCVSS 7.5EG 7.52026-01-20
A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2025-7745MEDIUMCVSS 5.8EG 5.82025-07-24
Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
- CVE-2026-0930MEDIUMCVSS 4.3EG 4.32026-04-20
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacent stack memory t…
- CVE-2026-11787MEDIUMCVSS 6.3EG 6.32026-06-09
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing…
- CVE-2026-14678MEDIUMCVSS 4.3EG 4.32026-08-13
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL …
- CVE-2026-18024MEDIUMCVSS 4.3EG 4.32026-08-13
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance …
- CVE-2026-18238MEDIUMCVSS 5.0EG 5.02026-09-05
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process m…
- CVE-2026-20311MEDIUMCVSS 6.3EG 6.32026-08-05
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is d…
- CVE-2026-20846HIGHCVSS 7.5EG 7.52026-02-10
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
- CVE-2026-21367HIGHCVSS 7.6EG 7.62026-04-06
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
- CVE-2026-21371HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when retrieving output buffer with insufficient size validation.
- CVE-2026-21373HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
- CVE-2026-21374HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.
- CVE-2026-21375HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
- CVE-2026-21376HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
- CVE-2026-21378HIGHCVSS 7.8EG 7.82026-04-06
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
- CVE-2026-21379HIGHCVSS 7.8EG 7.82026-07-06
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
- CVE-2026-21381HIGHCVSS 7.6EG 7.62026-04-06
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
- CVE-2026-2394MEDIUMCVSS 6.5EG 6.52026-04-01
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before …
- CVE-2026-24028HIGHCVSS 8.2EG 8.22026-03-31
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of s…
- CVE-2026-24075HIGHCVSS 7.8EG 7.82026-09-17
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
- CVE-2026-24081HIGHCVSS 7.4EG 7.42026-09-17
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
- CVE-2026-25275HIGHCVSS 7.5EG 7.52026-09-17
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
- CVE-2026-25284HIGHCVSS 7.3EG 7.32026-09-17
Information Disclosure when a pointer is reused after being deallocated.
- CVE-2026-25288HIGHCVSS 7.4EG 7.42026-08-04
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
- CVE-2026-25294HIGHCVSS 7.4EG 7.42026-09-17
Transient DOS while parsing frame during channel usage.
- CVE-2026-25646HIGHCVSS 8.1EG 8.12026-02-10
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function.…
- CVE-2026-26155MEDIUMCVSS 6.5EG 6.52026-04-14
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- CVE-2026-26169MEDIUMCVSS 6.1EG 6.12026-04-14
Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.
- CVE-2026-26184HIGHCVSS 7.8EG 7.82026-04-14
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-26271MEDIUMCVSS 5.3EG 5.32026-02-25
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data…
- CVE-2026-26282MEDIUMCVSS 6.6EG 6.62026-02-19
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file wi…
- CVE-2026-27798HIGHCVSS 7.1EG 7.12026-02-26
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small dimension using the `…
- CVE-2026-27799MEDIUMCVSS 4.4EG 4.42026-02-26
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occur…
- CVE-2026-28364HIGHCVSS 7.8EG 7.92026-02-27
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the r…
- CVE-2026-3203HIGHCVSS 7.5EG 7.52026-02-25
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
- CVE-2026-34059HIGHCVSS 7.5EG 7.52026-05-04
Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Map vulnerabilities like CWE-126 to your infrastructure
EchelonGraph correlates every CVE — across CWE-126 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →