Vulnerabilities (CVE)

Filtered by CWE-126
Total 292 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-21203 1 Microsoft 7 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 4 more 2025-07-10 N/A 6.5 MEDIUM
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-26664 1 Microsoft 7 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 4 more 2025-07-10 N/A 6.5 MEDIUM
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-26676 1 Microsoft 7 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 4 more 2025-07-09 N/A 6.5 MEDIUM
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-26672 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-07-09 N/A 6.5 MEDIUM
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-24068 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-07-08 N/A 5.5 MEDIUM
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2023-28267 1 Microsoft 14 Remote Desktop Client, Windows 10 1507, Windows 10 1607 and 11 more 2025-07-07 N/A 6.5 MEDIUM
Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2025-24992 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 21h2 and 11 more 2025-07-03 N/A 5.5 MEDIUM
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
CVE-2025-47295 1 Fortinet 1 Fortios 2025-06-04 N/A 3.7 LOW
A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.
CVE-2023-51773 1 Bacnetstack 1 Bacnet Stack 2025-05-23 N/A 9.1 CRITICAL
BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.
CVE-2025-32704 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2025-05-19 N/A 8.4 HIGH
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29956 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-05-19 N/A 5.4 MEDIUM
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
CVE-2024-45568 1 Qualcomm 26 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 23 more 2025-05-09 N/A 6.7 MEDIUM
Memory corruption due to improper bounds check while command handling in camera-kernel driver.
CVE-2024-49846 1 Qualcomm 62 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 59 more 2025-05-09 N/A 8.2 HIGH
Memory corruption while decoding of OTA messages from T3448 IE.
CVE-2024-49847 1 Qualcomm 94 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 91 more 2025-05-09 N/A 7.5 HIGH
Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.
CVE-2024-11596 1 Wireshark 1 Wireshark 2025-05-07 N/A 7.8 HIGH
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file
CVE-2025-21176 3 Apple, Linux, Microsoft 20 Macos, Linux Kernel, .net and 17 more 2025-05-06 N/A 8.8 HIGH
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
CVE-2023-38144 1 Microsoft 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more 2025-04-08 N/A 7.8 HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2023-6936 1 Wolfssl 1 Wolfssl 2025-03-26 N/A 5.3 MEDIUM
In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging).
CVE-2024-49838 1 Qualcomm 338 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 335 more 2025-02-05 N/A 8.2 HIGH
Information disclosure while parsing the OCI IE with invalid length.
CVE-2024-38404 1 Qualcomm 80 Ar8035, Ar8035 Firmware, Fastconnect 7800 and 77 more 2025-02-05 N/A 7.5 HIGH
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.