CWE-126

Buffer Over-read

Parent: CWE-125 - Out-of-bounds Read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

449 vulnerabilities with CWE-126
CVE-2024-11596 HIGH
Wireshark 4.2.0-4.2.8 and 4.4.0-4.4.1 - Denial of Service via ECMP Dissector
CVSS 7.8
CVE-2024-49031 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Graphics Buffer Over-read
CVSS 7.8
CVE-2024-9843 MEDIUM
Ivanti Secure Access Client < 22.7R4 - Unauthenticated Denial of Service via Buffer Over-Read
CVSS 5.0
CVE-2024-38405 HIGH
Qualcomm WSA8845H and other Firmware - Denial of Service via CU Information Processing
CVSS 7.5
CVE-2024-38403 HIGH
Qualcomm WSA/WCN/WCD Firmware - Denial of Service via BTM ML IE Parsing
CVSS 7.5
CVE-2024-43595 MEDIUM
Microsoft Edge Chromium < 130.0.2849.46 - Remote Code Execution
CVSS 6.5
CVE-2024-43500 MEDIUM
Windows 11 22H2/23H2/24H2 and Windows Server 2022 23H2 - Information Disclosure via ReFS Buffer Over-read
CVSS 5.5
CVE-2024-38265 HIGH
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 8.8
CVE-2024-38261 HIGH
Windows Routing and Remote Access Service - Remote Code Execution
CVSS 7.8
CVE-2024-38397 HIGH
Qualcomm Wi-Fi Firmware - Denial of Service via Probe Response and Association Response Frame Parsing
CVSS 7.5
CVE-2024-33073 HIGH
Qualcomm WSA8845H and other Firmware - Out-of-bounds Read in ML IE Parser
CVSS 8.2
CVE-2024-33071 HIGH
Qualcomm MDM9628 QCA6564A QCA6564AU QCA6574A QCA6574AU Firmware - Denial of Service via MBSSID IE Parsing
CVSS 7.5
CVE-2024-33070 HIGH
Qualcomm QCA6574AU/QCA6574A/QCA6564AU/QCA6564A/MDM9628 Firmware - Denial of Service via ESP IE Parsing
CVSS 7.5
CVE-2024-33064 HIGH
Qualcomm QCA6574AU Firmware - Out-of-bounds Read in Multiple MBSSID IE Parser
CVSS 8.2
CVE-2024-33049 HIGH
Qualcomm Snapdragon W5+ Gen 1 Wearable Platform Firmware - Denial of Service via Beacon Frame Parsing
CVSS 7.5
CVE-2024-9029 HIGH
FreeImage - Buffer Over-read in IPTC Profile Processing
CVSS 7.5
CVE-2024-43475 HIGH
Windows Server 2008 - Information Disclosure via Buffer Over-read
CVSS 7.3
CVE-2024-38250 HIGH
Windows Graphics Component - Privilege Escalation
CVSS 7.8
CVE-2024-33057 HIGH
Qualcomm AR8035 Firmware - Denial of Service via Multi-Link Element Control Field Parsing
CVSS 7.5
CVE-2024-33051 HIGH
Qualcomm 315 5G IoT Firmware - Denial of Service via TIM IE Length Check Bypass
CVSS 7.5
CVE-2024-33050 HIGH
Qualcomm AR8035 Firmware - Denial of Service via MBSSID IE Parsing
CVSS 7.5
CVE-2024-33048 HIGH
Qualcomm AR8035 Firmware - Denial of Service via TID-to-Link Mapping Element Parsing
CVSS 7.5
CVE-2024-33047 HIGH
Qualcomm Fastconnect 6700 Firmware - Buffer Over-read
CVSS 8.4
CVE-2024-33043 MEDIUM
Qualcomm APQ8017 Firmware - Denial of Service via PS Event Handling
CVSS 5.5
CVE-2024-23364 HIGH
Qualcomm AR8035 and FastConnect Firmware - Denial of Service via MBSSID Information Element Processing
CVSS 7.5
Details
Vulnerabilities 449