CWE-126
Buffer Over-read
Common consequences3
- ConfidentialityRead Memory
- ConfidentialityBypass Protection Mechanism
By reading out-of-bounds memory, an attacker might be able to get secret values, such as memory addresses, which can bypass protection mechanisms such as ASLR in order to improve the reliability and likelihood of exploiting a separate weakness to achieve code execution instead of just denial of service.
- AvailabilityIntegrityDoS: Crash, Exit, or Restart
An attacker might be able to cause a crash or other denial of service by causing the product to read a memory location that is not allowed (such as a segmentation fault), or to cause other conditions in which the read operation returns more data than is expected.
CVEs referencing this CWE100
| CVE | Description | Severity | EPSS | Flags | Modified |
|---|---|---|---|---|---|
| CVE-2023-49285 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability. | HIGH7.5 | 89%p100 | 2025-02-13 | |
| CVE-2017-7668 | The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value. | HIGH7.5 | 57%p99 | 2026-05-13 | |
| CVE-2009-2495 | The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability." | MEDIUM6.5 | 42%p99 | 2026-05-27 | |
| CVE-2017-7679 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header. | NONE | 39%p98 | PoC | 2026-05-13 |
| CVE-2025-21277 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH7.5 | 36%p98 | 2026-06-09 | |
| CVE-2024-38071 | Windows Remote Desktop Licensing Service Denial of Service Vulnerability | HIGH7.5 | 36%p98 | 2026-02-10 | |
| CVE-2024-20290 | A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog . | HIGH7.5 | 33%p98 | 2025-02-13 | |
| CVE-2023-38152 | DHCP Server Service Information Disclosure Vulnerability | MEDIUM5.3 | 24%p98 | 2025-10-30 | |
| CVE-2023-36397 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | CRITICAL9.8 | 18%p97 | 2025-10-08 | |
| CVE-2024-26160 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | MEDIUM5.5 | 11%p95 | PoC | 2025-05-03 |
| CVE-2006-7197 | The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory. | NONE | 8.32%p94 | 2026-04-23 | |
| CVE-2019-11036 | When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash. | CRITICAL9.1 | 6.84%p93 | 2024-11-21 | |
| CVE-2018-14790 | Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on the device. | NONE | 5.38%p92 | 2024-11-21 | |
| CVE-2023-38144 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH7.8 | 5.36%p92 | 2025-10-30 | |
| CVE-2018-8789 | FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault). | NONE | 5.24%p91 | 2024-11-21 | |
| CVE-2023-28266 | Windows Common Log File System Driver Information Disclosure Vulnerability | MEDIUM5.5 | 4.72%p91 | 2025-01-23 | |
| CVE-2018-8799 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault). | NONE | 4.07%p89 | 2024-11-21 | |
| CVE-2018-8796 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (segfault). | NONE | 4.07%p89 | 2024-11-21 | |
| CVE-2018-8792 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that results in a Denial of Service (segfault). | NONE | 4.07%p89 | 2024-11-21 | |
| CVE-2018-8798 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak. | NONE | 3.83%p89 | 2024-11-21 | |
| CVE-2018-8791 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak. | NONE | 3.83%p89 | 2024-11-21 | |
| CVE-2023-35638 | DHCP Server Service Denial of Service Vulnerability | HIGH7.5 | 3.26%p87 | 2025-01-01 | |
| CVE-2023-35643 | DHCP Server Service Information Disclosure Vulnerability | HIGH7.5 | 2.65%p84 | 2025-01-01 | |
| CVE-2023-36392 | DHCP Server Service Denial of Service Vulnerability | HIGH7.5 | 2.46%p82 | 2025-10-08 | |
| CVE-2026-26169 | Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally. | MEDIUM6.1 | 2.42%p82 | 2026-06-01 | |
| CVE-2023-36581 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH7.5 | 2.40%p82 | 2025-04-14 | |
| CVE-2024-27280 | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2. | CRITICAL9.8 | 2.36%p82 | 2026-04-15 | |
| CVE-2025-21176 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | HIGH8.8 | 2.26%p81 | 2026-06-09 | |
| CVE-2020-8244 | A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls. | MEDIUM6.5 | 2.12%p79 | 2024-11-21 | |
| CVE-2022-1720 | Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution. | HIGH7.8 | 2.10%p79 | 2024-11-21 | |
| CVE-2023-28267 | Remote Desktop Protocol Client Information Disclosure Vulnerability | MEDIUM6.5 | 2.09%p79 | 2025-07-07 | |
| CVE-2023-24942 | Remote Procedure Call Runtime Denial of Service Vulnerability | HIGH7.5 | 1.90%p77 | 2025-07-10 | |
| CVE-2022-1629 | Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution | HIGH7.8 | 1.84%p76 | 2024-11-21 | |
| CVE-2023-38172 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | HIGH7.5 | 1.79%p76 | 2025-02-27 | |
| CVE-2024-43475 | Microsoft Windows Admin Center Information Disclosure Vulnerability | HIGH7.3 | 1.72%p74 | 2024-12-31 | |
| CVE-2019-3563 | Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00 | CRITICAL9.8 | 1.71%p74 | 2024-11-21 | |
| CVE-2023-21701 | Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability | HIGH7.5 | 1.65%p73 | 2025-01-01 | |
| CVE-2023-21813 | Windows Secure Channel Denial of Service Vulnerability | HIGH7.5 | 1.65%p73 | 2025-01-01 | |
| CVE-2023-21811 | Windows iSCSI Service Denial of Service Vulnerability | HIGH7.5 | 1.65%p73 | 2025-01-01 | |
| CVE-2023-35330 | Windows Extended Negotiation Denial of Service Vulnerability | HIGH7.5 | 1.64%p73 | 2025-01-01 | |
| CVE-2024-38127 | Windows Hyper-V Elevation of Privilege Vulnerability | HIGH7.8 | 1.62%p73 | PoC | 2025-07-10 |
| CVE-2022-1927 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | HIGH7.8 | 1.60%p73 | 2024-11-21 | |
| CVE-2023-24901 | Windows NFS Portmapper Information Disclosure Vulnerability | HIGH7.5 | 1.59%p72 | 2025-07-10 | |
| CVE-2019-5432 | A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding. | HIGH7.5 | 1.59%p72 | 2024-11-21 | |
| CVE-2023-36801 | DHCP Server Service Information Disclosure Vulnerability | MEDIUM5.3 | 1.50%p71 | 2025-10-30 | |
| CVE-2021-1373 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insufficient validation of CAPWAP packets. An attacker could exploit this vulnerability by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. | HIGH8.6 | 1.49%p71 | 2024-11-21 | |
| CVE-2022-2124 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | HIGH7.8 | 1.48%p71 | 2024-11-21 | |
| CVE-2025-26672 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | MEDIUM6.5 | 1.47%p70 | 2026-02-13 | |
| CVE-2025-26664 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | MEDIUM6.5 | 1.47%p70 | 2026-02-13 | |
| CVE-2021-1588 | A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when an affected device is processing an MPLS echo-request or echo-reply packet. An attacker could exploit this vulnerability by sending malicious MPLS echo-request or echo-reply packets to an interface that is enabled for MPLS forwarding on the affected device. A successful exploit could allow the attacker to cause the MPLS OAM process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition. | HIGH8.6 | 1.47%p70 | 2024-11-21 | |
| CVE-2023-24883 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | MEDIUM6.5 | 1.46%p70 | 2025-02-28 | |
| CVE-2023-24870 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | MEDIUM6.5 | 1.46%p70 | 2025-02-28 | |
| CVE-2023-24857 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | MEDIUM6.5 | 1.46%p70 | 2025-02-28 | |
| CVE-2023-33173 | Remote Procedure Call Runtime Denial of Service Vulnerability | HIGH7.5 | 1.44%p70 | 2025-01-01 | |
| CVE-2023-33172 | Remote Procedure Call Runtime Denial of Service Vulnerability | HIGH7.5 | 1.44%p70 | 2025-01-01 | |
| CVE-2023-33169 | Remote Procedure Call Runtime Denial of Service Vulnerability | HIGH7.5 | 1.44%p70 | 2025-01-01 | |
| CVE-2023-33168 | Remote Procedure Call Runtime Denial of Service Vulnerability | HIGH7.5 | 1.44%p70 | 2025-01-01 | |
| CVE-2023-33167 | Remote Procedure Call Runtime Denial of Service Vulnerability | HIGH7.5 | 1.44%p70 | 2025-01-01 | |
| CVE-2023-33166 | Remote Procedure Call Runtime Denial of Service Vulnerability | HIGH7.5 | 1.44%p70 | 2025-01-01 | |
| CVE-2023-24858 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | HIGH7.5 | 1.43%p69 | 2025-02-28 | |
| CVE-2022-20714 | A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to the incorrect handling of malformed packets that are received on the Lightspeed-Plus line cards. An attacker could exploit this vulnerability by sending a crafted IPv4 or IPv6 packet through an affected device. A successful exploit could allow the attacker to cause the Lightspeed-Plus line card to reset, resulting in a denial of service (DoS) condition for any traffic that traverses that line card. | HIGH8.6 | 1.38%p69 | 2024-11-21 | |
| CVE-2021-34325 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affected applications lacks proper validation of user-supplied data when parsing JT files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13421) | MEDIUM5.5 | 1.35%p68 | 2024-11-21 | |
| CVE-2021-34321 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The VisDraw.dll library in affected applications lacks proper validation of user-supplied data when parsing J2K files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13414) | MEDIUM5.5 | 1.35%p68 | 2024-11-21 | |
| CVE-2021-34320 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Jt981.dll library in affected applications lacks proper validation of user-supplied data when parsing JT files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13406) | MEDIUM5.5 | 1.35%p68 | 2024-11-21 | |
| CVE-2021-34308 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13344) | MEDIUM5.5 | 1.35%p68 | 2024-11-21 | |
| CVE-2021-34307 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13343) | MEDIUM5.5 | 1.35%p68 | 2024-11-21 | |
| CVE-2021-34304 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13199) | MEDIUM5.5 | 1.35%p68 | 2024-11-21 | |
| CVE-2021-34303 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13198) | MEDIUM5.5 | 1.35%p68 | 2024-11-21 | |
| CVE-2021-34302 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13197) | MEDIUM5.5 | 1.35%p68 | 2024-11-21 | |
| CVE-2021-34299 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Tiff_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing TIFF files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13192) | MEDIUM5.5 | 1.35%p68 | 2024-11-21 | |
| CVE-2020-3399 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insufficient input validation during CAPWAP packet processing. An attacker could exploit this vulnerability by sending a crafted CAPWAP packet to an affected device, resulting in a buffer over-read. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition on the affected device. | HIGH8.6 | 1.35%p68 | 2024-11-21 | |
| CVE-2019-1010220 | tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file. | NONE | 1.35%p68 | 2024-11-21 | |
| CVE-2026-20846 | Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. | HIGH7.5 | 1.34%p68 | 2026-05-11 | |
| CVE-2025-21203 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | MEDIUM6.5 | 1.34%p68 | 2026-02-13 | |
| CVE-2022-22519 | A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system. | HIGH7.5 | 1.33%p67 | 2024-11-21 | |
| CVE-2025-26676 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | MEDIUM6.5 | 1.32%p67 | 2026-02-13 | |
| CVE-2024-38265 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | HIGH8.8 | 1.31%p67 | 2026-06-09 | |
| CVE-2020-25853 | The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, _rt_md5_hmac_veneer() or _rt_hmac_sha1_veneer(), resulting in a stack buffer over-read which can be exploited for denial of service. An attacker can impersonate an Access Point and attack a vulnerable Wi-Fi client, by injecting a crafted packet into the WPA2 handshake. The attacker does not need to know the network's PSK. | HIGH7.5 | 1.25%p65 | 2024-11-21 | |
| CVE-2023-21720 | Microsoft Edge (Chromium-based) Tampering Vulnerability | MEDIUM5.3 | 1.22%p65 | 2025-02-28 | |
| CVE-2021-1614 | A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory. This vulnerability is due to insufficient handling of malformed MPLS packets that are processed by a device that is running Cisco SD-WAN Software. An attacker could exploit this vulnerability by sending a crafted MPLS packet to an affected device that is running Cisco SD-WAN Software or Cisco SD-WAN vManage Software. A successful exploit could allow the attacker to gain unauthorized access to sensitive information. | MEDIUM5.3 | 1.19%p64 | 2024-11-21 | |
| CVE-2021-34322 | A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The JPEG2K_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing J2K files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-13416) | MEDIUM5.5 | 1.15%p63 | 2024-11-21 | |
| CVE-2025-53806 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | MEDIUM6.5 | 1.09%p61 | 2026-02-20 | |
| CVE-2025-53796 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | MEDIUM6.5 | 1.09%p61 | 2026-02-20 | |
| CVE-2025-53798 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | MEDIUM6.5 | 1.08%p61 | 2026-02-20 | |
| CVE-2025-53797 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | MEDIUM6.5 | 1.08%p61 | 2026-02-20 | |
| CVE-2021-34584 | Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. | CRITICAL9.1 | 1.08%p61 | 2025-08-15 | |
| CVE-2022-2175 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | HIGH7.8 | 1.07%p61 | 2024-11-21 | |
| CVE-2023-51773 | BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c. | CRITICAL9.1 | 1.05%p60 | 2025-05-23 | |
| CVE-2026-24028 | An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure. | HIGH8.2 | 1.03%p59 | 2026-04-14 | |
| CVE-2024-49088 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH7.8 | 1.01%p59 | 2026-06-09 | |
| CVE-2023-36803 | Windows Kernel Information Disclosure Vulnerability | MEDIUM5.5 | 1.00%p58 | 2025-10-30 | |
| CVE-2022-23130 | Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 and prior, Mitsubishi Electric ICONICS Suite versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 and prior, Mitsubishi Electric GENESIS32 versions 9.7 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.7 and prior allows an attacker to cause a DoS condition in the database server by getting a legitimate user to import a configuration file containing specially crafted stored procedures into GENESIS64, ICONICS Suite, MC Works64, or GENESIS32 and execute commands against the database from GENESIS64, ICONICS Suite, MC Works64, or GENESIS32. | MEDIUM5.5 | 1.00%p58 | 2026-01-08 | |
| CVE-2022-20823 | A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this vulnerability by sending a malicious OSPFv3 link-state advertisement (LSA) to an affected device. A successful exploit could allow the attacker to cause the OSPFv3 process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition. Note: The OSPFv3 feature is disabled by default. To exploit this vulnerability, an attacker must be able to establish a full OSPFv3 neighbor state with an affected device. For more information about exploitation conditions, see the Details section of this advisory. | HIGH8.6 | 0.99%p58 | 2024-11-21 | |
| CVE-2025-62473 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | MEDIUM6.5 | 0.98%p58 | 2026-04-16 | |
| CVE-2024-43595 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | HIGH8.8 | 0.97%p57 | 2026-06-09 | |
| CVE-2025-24992 | Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. | MEDIUM5.5 | 0.96%p57 | 2026-02-13 | |
| CVE-2023-23571 | An access violation vulnerability exists in the eventcore functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to denial of service. An attacker can send a network request to trigger this vulnerability. | HIGH7.5 | 0.93%p56 | 2024-11-21 | |
| CVE-2026-25646 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55. | HIGH8.1 | 0.91%p55 | 2026-02-13 | |
| CVE-2026-26155 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | MEDIUM6.5 | 0.89%p55 | 2026-06-01 | |
| CVE-2022-32141 | Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required. | MEDIUM6.5 | 0.88%p54 | 2024-11-21 |