CWE-126
AllowedBuffer Over-read
Abstraction: Variant · Status: Draft
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
978 vulnerabilities reference this CWE, most recent first.
GHSA-Q5HC-GPJW-FPVP
Vulnerability from github – Published: 2022-12-06 09:30 – Updated: 2022-12-07 18:30In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
{
"affected": [],
"aliases": [
"CVE-2022-39132"
],
"database_specific": {
"cwe_ids": [
"CWE-126",
"CWE-787"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-12-06T07:15:00Z",
"severity": "MODERATE"
},
"details": "In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.",
"id": "GHSA-q5hc-gpjw-fpvp",
"modified": "2022-12-07T18:30:28Z",
"published": "2022-12-06T09:30:24Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39132"
},
{
"type": "WEB",
"url": "https://www.unisoc.com/en_us/secy/announcementDetail/1599588060988411006"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-Q5HH-5V3V-96HC
Vulnerability from github – Published: 2026-09-08 18:32 – Updated: 2026-09-08 18:32Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
{
"affected": [],
"aliases": [
"CVE-2026-67390"
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-08T18:18:22Z",
"severity": "MODERATE"
},
"details": "Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.",
"id": "GHSA-q5hh-5v3v-96hc",
"modified": "2026-09-08T18:32:09Z",
"published": "2026-09-08T18:32:09Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67390"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67390"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-Q78V-HQCG-VC32
Vulnerability from github – Published: 2025-07-08 18:31 – Updated: 2025-07-08 18:31Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
{
"affected": [],
"aliases": [
"CVE-2025-49659"
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-07-08T17:15:48Z",
"severity": "HIGH"
},
"details": "Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.",
"id": "GHSA-q78v-hqcg-vc32",
"modified": "2025-07-08T18:31:46Z",
"published": "2025-07-08T18:31:46Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49659"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49659"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-Q9VW-2JGV-5P57
Vulnerability from github – Published: 2026-08-11 18:30 – Updated: 2026-08-11 18:30Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
{
"affected": [],
"aliases": [
"CVE-2026-53414"
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-11T16:17:32Z",
"severity": "MODERATE"
},
"details": "Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.",
"id": "GHSA-q9vw-2jgv-5p57",
"modified": "2026-08-11T18:30:47Z",
"published": "2026-08-11T18:30:47Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53414"
},
{
"type": "WEB",
"url": "https://www.zoom.com/en/trust/security-bulletin/zsb-26016"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-QC53-6PCV-3Q2P
Vulnerability from github – Published: 2025-05-15 18:31 – Updated: 2025-05-19 21:30An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, VariableServicesSetVariable () can be called by gRT_>SetVariable () or the SmmSetSensitiveVariable () or SmmInternalSetVariable () from SMM. In VariableServicesSetVariable (), it uses StrSize () to get variable name size, uses StrLen () to get variable name length and uses StrCmp () to compare strings. These actions may cause a buffer over-read.
{
"affected": [],
"aliases": [
"CVE-2024-52878"
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-15T16:15:32Z",
"severity": "HIGH"
},
"details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, VariableServicesSetVariable () can be called by gRT_\u003eSetVariable () or the SmmSetSensitiveVariable () or SmmInternalSetVariable () from SMM. In VariableServicesSetVariable (), it uses StrSize () to get variable name size, uses StrLen () to get variable name length and uses StrCmp () to compare strings. These actions may cause a buffer over-read.",
"id": "GHSA-qc53-6pcv-3q2p",
"modified": "2025-05-19T21:30:31Z",
"published": "2025-05-15T18:31:44Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52878"
},
{
"type": "WEB",
"url": "https://www.insyde.com/security-pledge"
},
{
"type": "WEB",
"url": "https://www.insyde.com/security-pledge/sa-2024016"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-QCVH-FFQ5-55F3
Vulnerability from github – Published: 2023-06-06 09:30 – Updated: 2024-04-04 04:34Transient DOS while parsing WLAN beacon or probe-response frame.
{
"affected": [],
"aliases": [
"CVE-2023-21661"
],
"database_specific": {
"cwe_ids": [
"CWE-125",
"CWE-126"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-06T08:15:12Z",
"severity": "HIGH"
},
"details": "Transient DOS while parsing WLAN beacon or probe-response frame.",
"id": "GHSA-qcvh-ffq5-55f3",
"modified": "2024-04-04T04:34:53Z",
"published": "2023-06-06T09:30:19Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-21661"
},
{
"type": "WEB",
"url": "https://www.qualcomm.com/company/product-security/bulletins/june-2023-bulletin"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-QCWV-WM5J-JGJ5
Vulnerability from github – Published: 2026-10-05 03:30 – Updated: 2026-10-05 12:31In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8912.
{
"affected": [],
"aliases": [
"CVE-2026-20540"
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-10-05T02:16:53Z",
"severity": "MODERATE"
},
"details": "In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8912.",
"id": "GHSA-qcwv-wm5j-jgj5",
"modified": "2026-10-05T12:31:23Z",
"published": "2026-10-05T03:30:26Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20540"
},
{
"type": "WEB",
"url": "https://www.mediatek.com/product-security-bulletin/October-2026"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-QF6X-7G55-4WGC
Vulnerability from github – Published: 2023-02-14 00:30 – Updated: 2023-02-22 21:30Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.
{
"affected": [],
"aliases": [
"CVE-2023-0817"
],
"database_specific": {
"cwe_ids": [
"CWE-125",
"CWE-126"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-02-13T22:15:00Z",
"severity": "HIGH"
},
"details": "Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.",
"id": "GHSA-qf6x-7g55-4wgc",
"modified": "2023-02-22T21:30:39Z",
"published": "2023-02-14T00:30:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0817"
},
{
"type": "WEB",
"url": "https://github.com/gpac/gpac/commit/be9f8d395bbd196e3812e9cd80708f06bcc206f7"
},
{
"type": "WEB",
"url": "https://huntr.dev/bounties/cb730bc5-d79c-4de6-9e57-10e8c3ce2cf3"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-QFQH-8MHG-FCVW
Vulnerability from github – Published: 2026-09-29 18:32 – Updated: 2026-09-30 21:31The _nx_secure_x509_asn1_tlv_block_parse() function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.
The function reads the one-byte ASN.1 tag from the caller's buffer before checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns NX_SECURE_X509_ASN1_LENGTH_TOO_LONG, but the read has already happened one byte past the end of the buffer.
code:
nx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c
UINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,
USHORT *tlv_tag_class, ULONG *tlv_length,
const UCHAR **tlv_data, ULONG *header_length)
{
UINT current_index;
USHORT current_tag;
ULONG length;
ULONG length_bytes;
current_index = 0;
current_tag = buffer[current_index]; /* <-- read before the bounds check */
if (*buffer_length < 1)
{
return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);
}
The remainder of the function is correctly ordered. The multi-byte length path is guarded by length_bytes > 4 || length_bytes > *buffer_length before its read loop, the decoded value is checked against length > *buffer_length, and the second single-byte length read follows its own *buffer_length < 1 guard. The tag read is the only load placed ahead of its check.
{
"affected": [],
"aliases": [
"CVE-2026-102758"
],
"database_specific": {
"cwe_ids": [
"CWE-126"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-29T18:17:13Z",
"severity": "HIGH"
},
"details": "The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller\u0027s buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n USHORT *tlv_tag_class, ULONG *tlv_length,\n const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG length;\n\n\n\nULONG length_bytes;\n\n current_index = 0;\n current_tag = buffer[current_index]; /* \u003c-- read before the bounds check */\n if (*buffer_length \u003c 1)\n {\n return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes \u003e 4 || length_bytes \u003e *buffer_length` before its read loop, the decoded value is checked against `length \u003e *buffer_length`, and the second single-byte length read follows its own `*buffer_length \u003c 1` guard. The tag read is the only load placed ahead of its check.",
"id": "GHSA-qfqh-8mhg-fcvw",
"modified": "2026-09-30T21:31:59Z",
"published": "2026-09-29T18:32:04Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102758"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-QGVH-3GR3-J9PH
Vulnerability from github – Published: 2024-10-07 15:31 – Updated: 2024-10-07 15:31Transient DOS while parsing ESP IE from beacon/probe response frame.
{
"affected": [],
"aliases": [
"CVE-2024-33070"
],
"database_specific": {
"cwe_ids": [
"CWE-125",
"CWE-126"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-07T13:15:13Z",
"severity": "HIGH"
},
"details": "Transient DOS while parsing ESP IE from beacon/probe response frame.",
"id": "GHSA-qgvh-3gr3-j9ph",
"modified": "2024-10-07T15:31:39Z",
"published": "2024-10-07T15:31:39Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33070"
},
{
"type": "WEB",
"url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
No mitigation information available for this CWE.
No CAPEC attack patterns related to this CWE.