Vulnerabilities (CVE)

Filtered by CWE-126
Total 385 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-45919 1 Mesa3d 1 Mesa 2025-11-04 N/A 5.3 MEDIUM
Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.
CVE-2023-39541 1 Weston-embedded 1 Uc-tcp-ip 2025-11-04 N/A 5.9 MEDIUM
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv6 ICMPv6 packet.
CVE-2023-39540 1 Weston-embedded 1 Uc-tcp-ip 2025-11-04 N/A 5.9 MEDIUM
A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv4 ICMP packet.
CVE-2025-47362 2025-11-04 N/A 6.1 MEDIUM
Information disclosure while processing message from client with invalid payload.
CVE-2025-47368 2025-11-04 N/A 7.8 HIGH
Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing.
CVE-2025-27064 2025-11-04 N/A 6.1 MEDIUM
Information disclosure while registering commands from clients with diag through diagHal.
CVE-2024-42333 1 Zabbix 1 Zabbix 2025-11-03 N/A 2.7 LOW
The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read in src/libs/zbxmedia/email.c
CVE-2023-3649 1 Wireshark 1 Wireshark 2025-11-03 N/A 5.3 MEDIUM
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
CVE-2024-7347 1 F5 2 Nginx Open Source, Nginx Plus 2025-11-03 N/A 4.7 MEDIUM
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-32053 2025-11-03 N/A 6.5 MEDIUM
A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead to a heap buffer over-read.
CVE-2025-32052 2025-11-03 N/A 6.5 MEDIUM
A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over-read.
CVE-2025-62787 1 Wazuh 1 Wazuh 2025-11-03 N/A 7.5 HIGH
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) is incorrect. A compromised agent can cause a READ operation beyond the end of the allocated buffer (which may contain sensitive information) by sending a specially crafted message to the wazuh manager. An attacker who is able to craft and send an agent message to the wazuh manager can cause a buffer over-read and potentially access sensitive data. While the buffer over-read is always triggered while resolving the arguments of mdebug2, specific configuration options (analysisd.debug=2) need to be in place for the respective data to be leaked. This vulnerability is fixed in 4.10.2.
CVE-2025-62792 1 Wazuh 1 Wazuh 2025-11-03 N/A 7.5 HIGH
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not being properly NULL terminated during its allocation in OS_CleanMSG(). A compromised agent can cause a READ operation beyond the end of the allocated buffer (which may contain sensitive information) by sending a specially crafted message to the wazuh manager. An attacker who is able to craft and send an agent message to the wazuh manager can cause a buffer over-read and potentially access sensitive data. This vulnerability is fixed in 4.12.0.
CVE-2025-11616 1 Amazon 1 Freertos-plus-tcp 2025-10-31 N/A 5.4 MEDIUM
A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect applications using IPv6. Users should upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.
CVE-2025-11617 1 Amazon 1 Freertos-plus-tcp 2025-10-31 N/A 5.4 MEDIUM
A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6. We recommend users upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.
CVE-2025-55081 1 Eclipse 1 Threadx Netx Duo 2025-10-27 N/A 9.1 CRITICAL
In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hello message: the ciphersuite length and compression method length. In case of an attacker-crafted message with values outside of the expected range, it could cause an out-of-bound read.
CVE-2025-60729 1 Perfree 1 Perfreeblog 2025-10-27 N/A 5.3 MEDIUM
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
CVE-2025-55093 1 Eclipse 1 Threadx Netx Duo 2025-10-24 N/A 5.3 MEDIUM
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corruption of 4 bytes of memory.
CVE-2025-55092 1 Eclipse 1 Threadx Netx Duo 2025-10-24 N/A 5.3 MEDIUM
In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with the timestamp option.
CVE-2025-55325 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-10-23 N/A 5.5 MEDIUM
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.