cvekit
LIVE
All CWEs

CWE-126

Buffer Over-read

VariantDraftSimple100 CVEs
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Common consequences3

  • ConfidentialityRead Memory
  • ConfidentialityBypass Protection Mechanism

    By reading out-of-bounds memory, an attacker might be able to get secret values, such as memory addresses, which can bypass protection mechanisms such as ASLR in order to improve the reliability and likelihood of exploiting a separate weakness to achieve code execution instead of just denial of service.

  • AvailabilityIntegrityDoS: Crash, Exit, or Restart

    An attacker might be able to cause a crash or other denial of service by causing the product to read a memory location that is not allowed (such as a segmentation fault), or to cause other conditions in which the read operation returns more data than is expected.

Relationships2

CVEs referencing this CWE100

CVEDescriptionSeverityEPSSFlagsModified
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

HIGH7.5
89%p100
2025-02-13
CVE-2017-7668

The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.

HIGH7.5
57%p99
2026-05-13
CVE-2009-2495

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."

MEDIUM6.5
42%p99
2026-05-27
CVE-2017-7679

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.

NONE
39%p98
PoC
2026-05-13
CVE-2025-21277

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

HIGH7.5
36%p98
2026-06-09
CVE-2024-38071

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

HIGH7.5
36%p98
2026-02-10
CVE-2024-20290

A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .

HIGH7.5
33%p98
2025-02-13
CVE-2023-38152

DHCP Server Service Information Disclosure Vulnerability

MEDIUM5.3
24%p98
2025-10-30
CVE-2023-36397

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CRITICAL9.8
18%p97
2025-10-08
CVE-2024-26160

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

MEDIUM5.5
11%p95
PoC
2025-05-03
CVE-2006-7197

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

NONE
8.32%p94
2026-04-23
CVE-2019-11036

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

CRITICAL9.1
6.84%p93
2024-11-21
CVE-2018-14790

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on the device.

NONE
5.38%p92
2024-11-21
CVE-2023-38144

Windows Common Log File System Driver Elevation of Privilege Vulnerability

HIGH7.8
5.36%p92
2025-10-30
CVE-2018-8789

FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).

NONE
5.24%p91
2024-11-21
CVE-2023-28266

Windows Common Log File System Driver Information Disclosure Vulnerability

MEDIUM5.5
4.72%p91
2025-01-23
CVE-2018-8799

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).

NONE
4.07%p89
2024-11-21
CVE-2018-8796

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (segfault).

NONE
4.07%p89
2024-11-21
CVE-2018-8792

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that results in a Denial of Service (segfault).

NONE
4.07%p89
2024-11-21
CVE-2018-8798

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak.

NONE
3.83%p89
2024-11-21
CVE-2018-8791

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak.

NONE
3.83%p89
2024-11-21
CVE-2023-35638

DHCP Server Service Denial of Service Vulnerability

HIGH7.5
3.26%p87
2025-01-01
CVE-2023-35643

DHCP Server Service Information Disclosure Vulnerability

HIGH7.5
2.65%p84
2025-01-01
CVE-2023-36392

DHCP Server Service Denial of Service Vulnerability

HIGH7.5
2.46%p82
2025-10-08
CVE-2026-26169

Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.

MEDIUM6.1
2.42%p82
2026-06-01
CVE-2023-36581

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

HIGH7.5
2.40%p82
2025-04-14
CVE-2024-27280

A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.

CRITICAL9.8
2.36%p82
2026-04-15
CVE-2025-21176

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

HIGH8.8
2.26%p81
2026-06-09
CVE-2020-8244

A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.

MEDIUM6.5
2.12%p79
2024-11-21
CVE-2022-1720

Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

HIGH7.8
2.10%p79
2024-11-21
CVE-2023-28267

Remote Desktop Protocol Client Information Disclosure Vulnerability

MEDIUM6.5
2.09%p79
2025-07-07
CVE-2023-24942

Remote Procedure Call Runtime Denial of Service Vulnerability

HIGH7.5
1.90%p77
2025-07-10
CVE-2022-1629

Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution

HIGH7.8
1.84%p76
2024-11-21
CVE-2023-38172

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

HIGH7.5
1.79%p76
2025-02-27
CVE-2024-43475

Microsoft Windows Admin Center Information Disclosure Vulnerability

HIGH7.3
1.72%p74
2024-12-31
CVE-2019-3563

Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00

CRITICAL9.8
1.71%p74
2024-11-21
CVE-2023-21701

Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability

HIGH7.5
1.65%p73
2025-01-01
CVE-2023-21813

Windows Secure Channel Denial of Service Vulnerability

HIGH7.5
1.65%p73
2025-01-01
CVE-2023-21811

Windows iSCSI Service Denial of Service Vulnerability

HIGH7.5
1.65%p73
2025-01-01
CVE-2023-35330

Windows Extended Negotiation Denial of Service Vulnerability

HIGH7.5
1.64%p73
2025-01-01
CVE-2024-38127

Windows Hyper-V Elevation of Privilege Vulnerability

HIGH7.8
1.62%p73
PoC
2025-07-10
CVE-2022-1927

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

HIGH7.8
1.60%p73
2024-11-21
CVE-2023-24901

Windows NFS Portmapper Information Disclosure Vulnerability

HIGH7.5
1.59%p72
2025-07-10
CVE-2019-5432

A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.

HIGH7.5
1.59%p72
2024-11-21
CVE-2023-36801

DHCP Server Service Information Disclosure Vulnerability

MEDIUM5.3
1.50%p71
2025-10-30
CVE-2021-1373

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insufficient validation of CAPWAP packets. An attacker could exploit this vulnerability by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.

HIGH8.6
1.49%p71
2024-11-21
CVE-2022-2124

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

HIGH7.8
1.48%p71
2024-11-21
CVE-2025-26672

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

MEDIUM6.5
1.47%p70
2026-02-13
CVE-2025-26664

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

MEDIUM6.5
1.47%p70
2026-02-13
CVE-2021-1588

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply packet. An attacker could exploit this vulnerability by sending malicious MPLS echo-request or echo-reply packets to an interface that is enabled for MPLS forwarding on the affected device. A successful exploit could allow the attacker to cause the MPLS OAM process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition.

HIGH8.6
1.47%p70
2024-11-21
CVE-2023-24883

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

MEDIUM6.5
1.46%p70
2025-02-28
CVE-2023-24870

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

MEDIUM6.5
1.46%p70
2025-02-28
CVE-2023-24857

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

MEDIUM6.5
1.46%p70
2025-02-28
CVE-2023-33173

Remote Procedure Call Runtime Denial of Service Vulnerability

HIGH7.5
1.44%p70
2025-01-01
CVE-2023-33172

Remote Procedure Call Runtime Denial of Service Vulnerability

HIGH7.5
1.44%p70
2025-01-01
CVE-2023-33169

Remote Procedure Call Runtime Denial of Service Vulnerability

HIGH7.5
1.44%p70
2025-01-01
CVE-2023-33168

Remote Procedure Call Runtime Denial of Service Vulnerability

HIGH7.5
1.44%p70
2025-01-01
CVE-2023-33167

Remote Procedure Call Runtime Denial of Service Vulnerability

HIGH7.5
1.44%p70
2025-01-01
CVE-2023-33166

Remote Procedure Call Runtime Denial of Service Vulnerability

HIGH7.5
1.44%p70
2025-01-01
CVE-2023-24858

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

HIGH7.5
1.43%p69
2025-02-28
CVE-2022-20714

A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to the incorrect handling of malformed packets that are received on the Lightspeed-Plus line cards. An attacker could exploit this vulnerability by sending a crafted IPv4 or IPv6 packet through an affected device. A successful exploit could allow the attacker to cause the Lightspeed-Plus line card to reset, resulting in a denial of service (DoS) condition for any traffic that traverses that line card.

HIGH8.6
1.38%p69
2024-11-21
CVE-2021-34325

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affected applications lacks proper validation of user-supplied data when parsing JT files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13421)

MEDIUM5.5
1.35%p68
2024-11-21
CVE-2021-34321

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The VisDraw.dll library in affected applications lacks proper validation of user-supplied data when parsing J2K files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13414)

MEDIUM5.5
1.35%p68
2024-11-21
CVE-2021-34320

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affected applications lacks proper validation of user-supplied data when parsing JT files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13406)

MEDIUM5.5
1.35%p68
2024-11-21
CVE-2021-34308

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13344)

MEDIUM5.5
1.35%p68
2024-11-21
CVE-2021-34307

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13343)

MEDIUM5.5
1.35%p68
2024-11-21
CVE-2021-34304

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13199)

MEDIUM5.5
1.35%p68
2024-11-21
CVE-2021-34303

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13198)

MEDIUM5.5
1.35%p68
2024-11-21
CVE-2021-34302

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13197)

MEDIUM5.5
1.35%p68
2024-11-21
CVE-2021-34299

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13192)

MEDIUM5.5
1.35%p68
2024-11-21
CVE-2020-3399

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insufficient input validation during CAPWAP packet processing. An attacker could exploit this vulnerability by sending a crafted CAPWAP packet to an affected device, resulting in a buffer over-read. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device.

HIGH8.6
1.35%p68
2024-11-21
CVE-2019-1010220

tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.

NONE
1.35%p68
2024-11-21
CVE-2026-20846

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

HIGH7.5
1.34%p68
2026-05-11
CVE-2025-21203

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

MEDIUM6.5
1.34%p68
2026-02-13
CVE-2022-22519

A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.

HIGH7.5
1.33%p67
2024-11-21
CVE-2025-26676

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

MEDIUM6.5
1.32%p67
2026-02-13
CVE-2024-38265

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

HIGH8.8
1.31%p67
2026-06-09
CVE-2020-25853

The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, _rt_md5_hmac_veneer() or _rt_hmac_sha1_veneer(), resulting in a stack buffer over-read which can be exploited for denial of service. An attacker can impersonate an Access Point and attack a vulnerable Wi-Fi client, by injecting a crafted packet into the WPA2 handshake. The attacker does not need to know the network's PSK.

HIGH7.5
1.25%p65
2024-11-21
CVE-2023-21720

Microsoft Edge (Chromium-based) Tampering Vulnerability

MEDIUM5.3
1.22%p65
2025-02-28
CVE-2021-1614

A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory. This vulnerability is due to insufficient handling of malformed MPLS packets that are processed by a device that is running Cisco SD-WAN Software. An attacker could exploit this vulnerability by sending a crafted MPLS packet to an affected device that is running Cisco SD-WAN Software or Cisco SD-WAN vManage Software. A successful exploit could allow the attacker to gain unauthorized access to sensitive information.

MEDIUM5.3
1.19%p64
2024-11-21
CVE-2021-34322

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The JPEG2K_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing J2K files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13416)

MEDIUM5.5
1.15%p63
2024-11-21
CVE-2025-53806

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

MEDIUM6.5
1.09%p61
2026-02-20
CVE-2025-53796

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

MEDIUM6.5
1.09%p61
2026-02-20
CVE-2025-53798

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

MEDIUM6.5
1.08%p61
2026-02-20
CVE-2025-53797

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

MEDIUM6.5
1.08%p61
2026-02-20
CVE-2021-34584

Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

CRITICAL9.1
1.08%p61
2025-08-15
CVE-2022-2175

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

HIGH7.8
1.07%p61
2024-11-21
CVE-2023-51773

BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.

CRITICAL9.1
1.05%p60
2025-05-23
CVE-2026-24028

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure.

HIGH8.2
1.03%p59
2026-04-14
CVE-2024-49088

Windows Common Log File System Driver Elevation of Privilege Vulnerability

HIGH7.8
1.01%p59
2026-06-09
CVE-2023-36803

Windows Kernel Information Disclosure Vulnerability

MEDIUM5.5
1.00%p58
2025-10-30
CVE-2022-23130

Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 and prior, Mitsubishi Electric ICONICS Suite versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 and prior, Mitsubishi Electric GENESIS32 versions 9.7 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.7 and prior allows an attacker to cause a DoS condition in the database server by getting a legitimate user to import a configuration file containing specially crafted stored procedures into GENESIS64, ICONICS Suite, MC Works64, or GENESIS32 and execute commands against the database from GENESIS64, ICONICS Suite, MC Works64, or GENESIS32.

MEDIUM5.5
1.00%p58
2026-01-08
CVE-2022-20823

A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this vulnerability by sending a malicious OSPFv3 link-state advertisement (LSA) to an affected device. A successful exploit could allow the attacker to cause the OSPFv3 process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition. Note: The OSPFv3 feature is disabled by default. To exploit this vulnerability, an attacker must be able to establish a full OSPFv3 neighbor state with an affected device. For more information about exploitation conditions, see the Details section of this advisory.

HIGH8.6
0.99%p58
2024-11-21
CVE-2025-62473

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

MEDIUM6.5
0.98%p58
2026-04-16
CVE-2024-43595

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

HIGH8.8
0.97%p57
2026-06-09
CVE-2025-24992

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.

MEDIUM5.5
0.96%p57
2026-02-13
CVE-2023-23571

An access violation vulnerability exists in the eventcore functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to denial of service. An attacker can send a network request to trigger this vulnerability.

HIGH7.5
0.93%p56
2024-11-21
CVE-2026-25646

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.

HIGH8.1
0.91%p55
2026-02-13
CVE-2026-26155

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

MEDIUM6.5
0.89%p55
2026-06-01
CVE-2022-32141

Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.

MEDIUM6.5
0.88%p54
2024-11-21