CWE-126

Buffer Over-read

Parent: CWE-125 - Out-of-bounds Read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

449 vulnerabilities with CWE-126
CVE-2025-26672 MEDIUM
Windows 10 1507-24H2 and Windows Server 2008 - Unauthenticated Buffer Over-read in RRAS
CVSS 6.5
CVE-2025-26664 MEDIUM
Windows Server 2008-2025 Unauthenticated Info Disclosure via RRAS Buffer Over-read
CVSS 6.5
CVE-2025-21203 MEDIUM
Windows Server 2008-2025 Unauthenticated Buffer Over-read in RRAS
CVSS 6.5
CVE-2025-21448 HIGH
Qualcomm Firmware - Denial of Service via SSID Parsing in Action Frames
CVSS 7.5
CVE-2025-21435 HIGH
Qualcomm AR8035 Firmware - Denial of Service via Extended IE Beacon Parsing
CVSS 7.5
CVE-2025-21434 HIGH
Qualcomm Firmware - Denial of Service via EHT IE Parsing
CVSS 7.5
CVE-2025-21430 HIGH
Qualcomm 315 5G IoT Modem Firmware - Denial of Service via ADD TS Request
CVSS 7.5
CVE-2025-21429 HIGH
Qualcomm Snapdragon and Smart Platform Firmware - Buffer Over-read in ADD TS Request Handling
CVSS 7.5
CVE-2025-21428 HIGH
Qualcomm Snapdragon Firmware - Buffer Over-read in ADD TS Request Handling
CVSS 7.5
CVE-2025-21421 HIGH
Qualcomm AQT1000 and FastConnect Firmware - Buffer Over-read in Escape Code Processing
CVSS 7.8
CVE-2025-32053 MEDIUM
Red Hat Enterprise Linux 8 - Buffer Over-read in libsoup
CVSS 6.5
CVE-2025-32052 MEDIUM
Red Hat Enterprise Linux 8 - Buffer Over-read in libsoup sniff_unknown()
CVSS 6.5
CVE-2025-24992 MEDIUM
Windows NTFS - Unauthenticated Buffer Over-read
CVSS 5.5
CVE-2025-21277 HIGH
Windows 10 1507-24H2 and Windows Server 2008-2012 - Denial of Service via MSMQ Buffer Over-read
CVSS 7.5
CVE-2025-21271 HIGH
Windows Cloud Files Mini Filter Driver Elevation of Privilege
CVSS 7.8
CVE-2025-21176 HIGH
.NET and .NET Framework - Remote Code Execution
CVSS 8.8
CVE-2024-53026 HIGH
Qualcomm APQ8017 Firmware - Information Disclosure via Invalid RTCP Packet
CVSS 8.2
CVE-2024-53021 HIGH
Qualcomm QCM4490 Firmware - Information Disclosure via RTCP Goodbye Packet Processing
CVSS 8.2
CVE-2024-53020 HIGH
Qualcomm APQ8017 and other Firmware - Information Disclosure via RTP Packet Decoding
CVSS 8.2
CVE-2024-53019 HIGH
Qualcomm FastConnect and QCA Firmware - Buffer Over-read in RTP Packet Decoding
CVSS 8.2
CVE-2024-52879 HIGH
Insyde InsydeH2O 5.2-5.7 - Buffer Over-read in VariableRuntimeDxe Driver
CVSS 7.5
CVE-2024-52878 HIGH
Insyde InsydeH2O 5.2-5.7 - Buffer Over-read in VariableRuntimeDxe VariableServicesSetVariable
CVSS 7.5
CVE-2024-52877 HIGH
Insyde InsydeH2O 5.2-5.2.05.29.50 - Buffer Over-read in VariableRuntimeDxe Driver
CVSS 7.5
CVE-2024-49847 HIGH
Qualcomm OTA Registration Acceptance Firmware - Denial of Service
CVSS 7.5
CVE-2024-49846 HIGH
Qualcomm Firmware - Out-of-bounds Read in T3448 IE OTA Message Decoding
CVSS 8.2
Details
Vulnerabilities 449