Skip to content
Noroxi

CWE-126 · 518 records

Buffer Over-read

CVEs in this class

518 records

  • Denial of Service in HTTP Message Processing in Squid

    HighCVSS 7.5No exploitEPSS 88%

    squid-cache · squidDec 4, 2023

  • In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Co

    CriticalCVSS 9.8Proof of conceptEPSS 39%

    apache · http serverJun 19, 2017

  • The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token()

    HighCVSS 7.5No exploitEPSS 57%

    apache · http serverJun 19, 2017

  • Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 18%

    microsoft · windows 10 1507Nov 14, 2023

  • Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

    HighCVSS 7.5No exploitEPSS 39%

    microsoft · windows 10 1507Jan 14, 2025

  • Windows Remote Desktop Licensing Service Denial of Service Vulnerability

    HighCVSS 7.5No exploitEPSS 36%

    microsoft · windows server 2008Jul 9, 2024

  • Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace.

    CriticalCVSS 9.8No exploitEPSS 5%

    fujielectric · frenic loader 3.3 firmwareOct 1, 2018

  • A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS)

    HighCVSS 7.5No exploitEPSS 34%

    cisco · secure endpointFeb 7, 2024

  • Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow

    CriticalCVSS 9.8No exploitEPSS 2%

    facebook · wangleApr 29, 2019

  • Buffer Over-read in Data Modem

    CriticalCVSS 9.8No exploitEPSS 0%

    qualcomm · 315 5g iot modem firmwareOct 3, 2023

  • Multiple buffer overread vulnerabilities in WLAN

    CriticalCVSS 9.8No exploitEPSS 0%

    qualcomm · sd 450 firmwareNov 26, 2024

  • Buffer Over-read in WLAN Host Cmn

    CriticalCVSS 9.8No exploitEPSS 0%

    qualcomm · ar8035 firmwareFeb 3, 2025

  • Heap over-read in PHP EXIF extension

    CriticalCVSS 9.1No exploitEPSS 7%

    php · phpMay 3, 2019

  • .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 2%

    microsoft · .netJan 14, 2025

  • CODESYS V2 web server: crafted requests could trigger a buffer over-read (DoS)

    CriticalCVSS 9.1No exploitEPSS 1%

    wago · 750-823 firmwareOct 26, 2021

  • BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.

    CriticalCVSS 9.1No exploitEPSS 1%

    bacnetstack · bacnet stackFeb 28, 2024

  • Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP

    CriticalCVSS 9.1No exploitEPSS 1%

    openvpn · openvpnDec 1, 2025

  • Buffer Copy Without Checking Size of Input in Modem

    CriticalCVSS 9.1No exploitEPSS 0%

    qualcomm · ar8035 firmwareFeb 6, 2024

  • Buffer Over-read in Multi-Mode Call Processor

    CriticalCVSS 9.1No exploitEPSS 0%

    qualcomm · qca6688aq firmwareMay 6, 2025

  • Buffer Over-read in WLAN HOST

    CriticalCVSS 9.1No exploitEPSS 0%

    qualcomm · ar8035 firmwareJul 1, 2024

  • Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · edge chromiumAug 3, 2026

  • Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · edge chromiumOct 17, 2024

  • EOL .NET 6.0 Runtime Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · .net 6.0Sep 8, 2025

  • Buffer Over-read in WLAN HOST

    HighCVSS 8.8No exploitEPSS 0%

    qualcomm · csrb31024 firmwareNov 7, 2023

  • CVE-2021-1373
    34Monitor

    Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerability

    HighCVSS 8.6No exploitEPSS 1%

    cisco · ios xeMar 24, 2021

All vulnerability classes