CWE-126

Buffer Over-read

Parent: CWE-125 - Out-of-bounds Read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

449 vulnerabilities with CWE-126
CVE-2024-45568 MEDIUM
Qualcomm FastConnect 6900 Firmware - Out-of-bounds Read in Camera-Kernel Driver
CVSS 6.7
CVE-2024-45552 HIGH
Qualcomm APQ8064AU and FastConnect Firmware - Information Disclosure via Non-Conforming RTCP Packet
CVSS 8.2
CVE-2024-12975 LOW
Simplicity SDK < 2024.12.1 - Buffer Over-read via SPI Interface
CVE-2024-43056 MEDIUM
Qualcomm AQT1000 Firmware - Denial of Service via Hypervisor Virtual I/O Operation
CVSS 5.5
CVE-2024-57970 MEDIUM
libarchive <3.7.7 - Buffer Overflow
CVSS 4.0
CVE-2024-12011 HIGH
130.8005 TCP/IP Gateway <12h - Buffer Overflow
CVSS 7.6
CVE-2024-49839 HIGH
Qualcomm Firmware - Memory Corruption during Management Frame Processing
CVSS 8.2
CVE-2024-49838 HIGH
Qualcomm FastConnect and AR8035 Firmware - Information Disclosure via OCI IE
CVSS 8.2
CVE-2024-45561 HIGH
Qualcomm AQT1000 and FastConnect Firmware - Use-After-Free via IOCTL Latency Level Handling
CVSS 7.8
CVE-2024-38417 MEDIUM
Qualcomm IO Control Commands Firmware - Information Disclosure
CVSS 6.1
CVE-2024-38416 MEDIUM
Qualcomm Firmware - Information Disclosure During Audio Playback
CVSS 6.1
CVE-2024-38414 MEDIUM
Qualcomm FastConnect and Multiple Firmware - Information Disclosure
CVSS 6.1
CVE-2024-38404 HIGH
Qualcomm Modem Firmware - Denial of Service via OTA Registration
CVSS 7.5
CVE-2024-45559 MEDIUM
Qualcomm Firmware - Denial of Service via GVM Message to Vdev-FastRPC Backend
CVSS 5.5
CVE-2024-45558 HIGH
Qualcomm AR8035 Firmware - Denial of Service via Per STA Profile IE Parsing
CVSS 7.5
CVE-2024-45548 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2024-45546 HIGH
Product <Version - Memory Corruption
CVSS 7.8
CVE-2024-43063 MEDIUM
Product <Version> - Info Disclosure
CVSS 6.1
CVE-2024-33067 MEDIUM
Qualcomm AR8035 and other Firmware - Out-of-bounds Read in Sound Model Driver Callback
CVSS 6.1
CVE-2024-33061 MEDIUM
Qualcomm QCS8550 Firmware - Information Disclosure via Uninitialized Process Handling in IOCTL Call
CVSS 6.8
CVE-2024-23366 MEDIUM
Qualcomm Firmware - Information Disclosure via Mailbox Write API
CVSS 6.6
CVE-2024-49088 HIGH
Windows Common Log File System Driver - Elevation of Privilege via Buffer Over-read
CVSS 7.8
CVE-2024-33056 HIGH
Qualcomm Modem and FastConnect Firmware - Out-of-bounds Read in SMEM Partition Allocation
CVSS 8.4
CVE-2024-33037 MEDIUM
Qualcomm NPU Firmware - Information Disclosure via Invalid IPC Message
CVSS 6.1
CVE-2024-42333 LOW
Zabbix 6.0.0-6.0.33 - Buffer Over-read in Email Media Type Handling
CVSS 2.7
Details
Vulnerabilities 449