Common Weakness Enumeration

CWE-126

Allowed

Buffer Over-read

Abstraction: Variant · Status: Draft

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

978 vulnerabilities reference this CWE, most recent first.

GHSA-Q5HC-GPJW-FPVP

Vulnerability from github – Published: 2022-12-06 09:30 – Updated: 2022-12-07 18:30
VLAI
Details

In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-39132"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-126",
      "CWE-787"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-12-06T07:15:00Z",
    "severity": "MODERATE"
  },
  "details": "In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.",
  "id": "GHSA-q5hc-gpjw-fpvp",
  "modified": "2022-12-07T18:30:28Z",
  "published": "2022-12-06T09:30:24Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39132"
    },
    {
      "type": "WEB",
      "url": "https://www.unisoc.com/en_us/secy/announcementDetail/1599588060988411006"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-Q5HH-5V3V-96HC

Vulnerability from github – Published: 2026-09-08 18:32 – Updated: 2026-09-08 18:32
VLAI
Details

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-67390"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-126"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-08T18:18:22Z",
    "severity": "MODERATE"
  },
  "details": "Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.",
  "id": "GHSA-q5hh-5v3v-96hc",
  "modified": "2026-09-08T18:32:09Z",
  "published": "2026-09-08T18:32:09Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67390"
    },
    {
      "type": "WEB",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67390"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-Q78V-HQCG-VC32

Vulnerability from github – Published: 2025-07-08 18:31 – Updated: 2025-07-08 18:31
VLAI
Details

Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-49659"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-126"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-07-08T17:15:48Z",
    "severity": "HIGH"
  },
  "details": "Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.",
  "id": "GHSA-q78v-hqcg-vc32",
  "modified": "2025-07-08T18:31:46Z",
  "published": "2025-07-08T18:31:46Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49659"
    },
    {
      "type": "WEB",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49659"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-Q9VW-2JGV-5P57

Vulnerability from github – Published: 2026-08-11 18:30 – Updated: 2026-08-11 18:30
VLAI
Details

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-53414"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-126"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-08-11T16:17:32Z",
    "severity": "MODERATE"
  },
  "details": "Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.",
  "id": "GHSA-q9vw-2jgv-5p57",
  "modified": "2026-08-11T18:30:47Z",
  "published": "2026-08-11T18:30:47Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53414"
    },
    {
      "type": "WEB",
      "url": "https://www.zoom.com/en/trust/security-bulletin/zsb-26016"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-QC53-6PCV-3Q2P

Vulnerability from github – Published: 2025-05-15 18:31 – Updated: 2025-05-19 21:30
VLAI
Details

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, VariableServicesSetVariable () can be called by gRT_>SetVariable () or the SmmSetSensitiveVariable () or SmmInternalSetVariable () from SMM. In VariableServicesSetVariable (), it uses StrSize () to get variable name size, uses StrLen () to get variable name length and uses StrCmp () to compare strings. These actions may cause a buffer over-read.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-52878"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-126"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-05-15T16:15:32Z",
    "severity": "HIGH"
  },
  "details": "An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, VariableServicesSetVariable () can be called by gRT_\u003eSetVariable () or the SmmSetSensitiveVariable () or SmmInternalSetVariable () from SMM. In VariableServicesSetVariable (), it uses StrSize () to get variable name size, uses StrLen () to get variable name length and uses StrCmp () to compare strings. These actions may cause a buffer over-read.",
  "id": "GHSA-qc53-6pcv-3q2p",
  "modified": "2025-05-19T21:30:31Z",
  "published": "2025-05-15T18:31:44Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52878"
    },
    {
      "type": "WEB",
      "url": "https://www.insyde.com/security-pledge"
    },
    {
      "type": "WEB",
      "url": "https://www.insyde.com/security-pledge/sa-2024016"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-QCVH-FFQ5-55F3

Vulnerability from github – Published: 2023-06-06 09:30 – Updated: 2024-04-04 04:34
VLAI
Details

Transient DOS while parsing WLAN beacon or probe-response frame.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-21661"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-125",
      "CWE-126"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-06-06T08:15:12Z",
    "severity": "HIGH"
  },
  "details": "Transient DOS while parsing WLAN beacon or probe-response frame.",
  "id": "GHSA-qcvh-ffq5-55f3",
  "modified": "2024-04-04T04:34:53Z",
  "published": "2023-06-06T09:30:19Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-21661"
    },
    {
      "type": "WEB",
      "url": "https://www.qualcomm.com/company/product-security/bulletins/june-2023-bulletin"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-QCWV-WM5J-JGJ5

Vulnerability from github – Published: 2026-10-05 03:30 – Updated: 2026-10-05 12:31
VLAI
Details

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8912.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-20540"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-126"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-10-05T02:16:53Z",
    "severity": "MODERATE"
  },
  "details": "In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8912.",
  "id": "GHSA-qcwv-wm5j-jgj5",
  "modified": "2026-10-05T12:31:23Z",
  "published": "2026-10-05T03:30:26Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20540"
    },
    {
      "type": "WEB",
      "url": "https://www.mediatek.com/product-security-bulletin/October-2026"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-QF6X-7G55-4WGC

Vulnerability from github – Published: 2023-02-14 00:30 – Updated: 2023-02-22 21:30
VLAI
Details

Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-0817"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-125",
      "CWE-126"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-02-13T22:15:00Z",
    "severity": "HIGH"
  },
  "details": "Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.",
  "id": "GHSA-qf6x-7g55-4wgc",
  "modified": "2023-02-22T21:30:39Z",
  "published": "2023-02-14T00:30:21Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0817"
    },
    {
      "type": "WEB",
      "url": "https://github.com/gpac/gpac/commit/be9f8d395bbd196e3812e9cd80708f06bcc206f7"
    },
    {
      "type": "WEB",
      "url": "https://huntr.dev/bounties/cb730bc5-d79c-4de6-9e57-10e8c3ce2cf3"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-QFQH-8MHG-FCVW

Vulnerability from github – Published: 2026-09-29 18:32 – Updated: 2026-09-30 21:31
VLAI
Details

The _nx_secure_x509_asn1_tlv_block_parse() function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.

The function reads the one-byte ASN.1 tag from the caller's buffer before checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns NX_SECURE_X509_ASN1_LENGTH_TOO_LONG, but the read has already happened one byte past the end of the buffer.

code:

nx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c




UINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,

                                          USHORT *tlv_tag_class, ULONG *tlv_length,
                                          const UCHAR **tlv_data, ULONG *header_length)


{



UINT   current_index;



USHORT current_tag;



ULONG  length;



ULONG  length_bytes;

    current_index = 0;
    current_tag = buffer[current_index];      /* <-- read before the bounds check */
    if (*buffer_length < 1)
    {
        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);
    }


The remainder of the function is correctly ordered. The multi-byte length path is guarded by length_bytes > 4 || length_bytes > *buffer_length before its read loop, the decoded value is checked against length > *buffer_length, and the second single-byte length read follows its own *buffer_length < 1 guard. The tag read is the only load placed ahead of its check.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-102758"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-126"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-29T18:17:13Z",
    "severity": "HIGH"
  },
  "details": "The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller\u0027s buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* \u003c-- read before the bounds check */\n    if (*buffer_length \u003c 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes \u003e 4 || length_bytes \u003e *buffer_length` before its read loop, the decoded value is checked against `length \u003e *buffer_length`, and the second single-byte length read follows its own `*buffer_length \u003c 1` guard. The tag read is the only load placed ahead of its check.",
  "id": "GHSA-qfqh-8mhg-fcvw",
  "modified": "2026-09-30T21:31:59Z",
  "published": "2026-09-29T18:32:04Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102758"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-QGVH-3GR3-J9PH

Vulnerability from github – Published: 2024-10-07 15:31 – Updated: 2024-10-07 15:31
VLAI
Details

Transient DOS while parsing ESP IE from beacon/probe response frame.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-33070"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-125",
      "CWE-126"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-10-07T13:15:13Z",
    "severity": "HIGH"
  },
  "details": "Transient DOS while parsing ESP IE from beacon/probe response frame.",
  "id": "GHSA-qgvh-3gr3-j9ph",
  "modified": "2024-10-07T15:31:39Z",
  "published": "2024-10-07T15:31:39Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33070"
    },
    {
      "type": "WEB",
      "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2024-bulletin.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

No mitigation information available for this CWE.

No CAPEC attack patterns related to this CWE.