CWE-126: CWE-126

152
Total CVEs
4
Critical
111
High
7.3
Avg CVSS

Yearly Trend

2026
8
2025
65
2024
37
2023
32
2022
7

Top Affected Vendors

1 Qualcomm 86
2 Microsoft 34
3 Fedoraproject 3
4 Cisco 3
5 Vim 3
6 Wazuh 2
7 Eclipse 2
8 Codesys 2
9 Libmobi Project 2
10 Apple 2

All CWE-126 CVEs (152)

CVE-2017-17772
9.8

This vulnerability allows attackers to perform out-of-bounds reads in 802.11 frame processing functions due to insufficient input validation. It affec...

Nov 26, 2024
CVE-2023-36397
9.8

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General M...

Nov 14, 2023
CVE-2023-51773
9.1

This vulnerability in BACnet Stack allows attackers to read beyond allocated memory boundaries in the bacapp_decode_application_data function. It affe...

Feb 29, 2024
CVE-2021-34584
9.1

CVE-2021-34584 is a buffer over-read vulnerability in the CODESYS V2 web server that allows attackers to read partial stack or heap memory or cause de...

Oct 26, 2021
CVE-2025-21176
8.8

This vulnerability allows remote code execution in .NET, .NET Framework, and Visual Studio applications through a buffer overflow condition (CWE-126)....

Jan 14, 2025
CVE-2022-20714
8.6

This vulnerability allows unauthenticated remote attackers to cause Cisco ASR 9000 Series routers with Lightspeed-Plus line cards to reset by sending ...

Apr 15, 2022
CVE-2021-1588
8.6

An unauthenticated remote attacker can send malicious MPLS echo packets to cause a denial of service on vulnerable Cisco NX-OS devices. This vulnerabi...

Aug 25, 2021
CVE-2021-1373
8.6

This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending a malformed CAPWAP packet to affected Cisco...

Mar 24, 2021
CVE-2025-32704
8.4

A buffer over-read vulnerability in Microsoft Office Excel allows attackers to read beyond allocated memory boundaries, potentially leading to informa...

May 13, 2025
CVE-2024-33056
8.4

CVE-2024-33056 is a memory corruption vulnerability in Qualcomm's Shared Memory (SMEM) subsystem that allows attackers to potentially execute arbitrar...

Dec 2, 2024
CVE-2025-21487
8.2

This vulnerability allows attackers to read sensitive information from memory when User Equipment (UE) processes malformed RTP packets with manipulate...

Sep 24, 2025
CVE-2025-21427
8.2

This vulnerability allows information disclosure when a User Equipment (UE) device receives RTP packets from the network. It affects mobile devices wi...

Jul 8, 2025
CVE-2024-53019
8.2

This vulnerability allows attackers to read sensitive information from memory when processing malformed RTP packets with improper header lengths. It a...

Jun 3, 2025
CVE-2024-53021
8.2

This vulnerability allows information disclosure when processing RTCP goodbye packets in Qualcomm products. Attackers can exploit this to leak sensiti...

Jun 3, 2025
CVE-2024-45552
8.2

This vulnerability allows information disclosure during video calls when a device receives a malformed RTCP packet that doesn't conform to RFC standar...

Apr 7, 2025
CVE-2024-49838
8.2

This vulnerability allows attackers to read sensitive memory contents when parsing malformed OCI (Oracle Call Interface) information elements with inv...

Feb 3, 2025
CVE-2024-49839
8.2

This vulnerability allows memory corruption during Wi-Fi management frame processing due to a mismatch in T2LM (Target Wake Time Link Management) info...

Feb 3, 2025
CVE-2024-33073
8.2

This vulnerability allows attackers to read sensitive information from Wi-Fi chipsets when parsing Multi-Link Device (MLD) information elements. It af...

Oct 7, 2024
CVE-2023-33058
8.2

This vulnerability allows information disclosure in Qualcomm modem chipsets while processing System Information Block 5 (SIB5) messages. Attackers can...

Feb 6, 2024
CVE-2023-24848
8.2

This vulnerability allows information disclosure in Qualcomm data modems during VoLTE calls when an undefined RTCP FB line value is processed. Attacke...

Oct 3, 2023
CVE-2023-22385
8.2

This vulnerability allows memory corruption in Qualcomm data modem chipsets during mobile-originated or mobile-terminated VoLTE calls. Attackers could...

Oct 3, 2023
CVE-2023-21669
8.2

This vulnerability allows information disclosure in Qualcomm WLAN HOST software when sending DPP action frames with invalid source addresses. Attacker...

Jun 6, 2023
CVE-2022-40505
8.2

This vulnerability allows attackers to read sensitive information from modem memory due to a buffer over-read while parsing DNS hostnames. It affects ...

May 2, 2023
CVE-2022-40503
8.2

This vulnerability allows attackers to read sensitive information from Bluetooth-enabled devices during A2DP audio streaming. It affects devices with ...

Apr 13, 2023
CVE-2022-33295
8.2

This vulnerability allows attackers to read sensitive information from memory in Qualcomm modems due to a buffer over-read while parsing WMS messages....

Apr 13, 2023
CVE-2022-33291
8.2

This vulnerability in Qualcomm modems allows attackers to read sensitive information from device memory due to improper handling of malformed IP heade...

Apr 13, 2023
CVE-2022-33287
8.2

This vulnerability allows attackers to read sensitive information from modem memory due to a buffer over-read in IPv6 packet processing. It affects de...

Apr 13, 2023
CVE-2022-25747
8.2

CVE-2022-25747 is an information disclosure vulnerability in Qualcomm modems due to improper input validation when parsing CoAP (Constrained Applicati...

Apr 13, 2023
CVE-2022-25730
8.2

CVE-2022-25730 is an information disclosure vulnerability in Qualcomm modems where improper IP type checking during DNS server queries allows attacker...

Apr 13, 2023
CVE-2022-33229
8.2

This vulnerability allows attackers to read sensitive information from modem memory due to a buffer over-read when processing IPv4 packets. It affects...

Feb 12, 2023
CVE-2022-25728
8.2

CVE-2022-25728 is a buffer over-read vulnerability in Qualcomm modem firmware that allows information disclosure when processing DNS server responses....

Feb 12, 2023
CVE-2022-1908
8.1

CVE-2022-1908 is a buffer over-read vulnerability in libmobi library versions prior to 0.11 that allows reading beyond allocated memory boundaries whe...

May 27, 2022
CVE-2025-59600
7.8

This CVE describes a buffer overflow vulnerability in Qualcomm software where user-supplied data is added without proper bounds checking, leading to m...

Mar 2, 2026
CVE-2025-60720
7.8

A buffer over-read vulnerability in Windows TDX.sys allows an authenticated attacker to read beyond allocated memory boundaries, potentially leading t...

Nov 11, 2025
CVE-2025-47368
7.8

This vulnerability allows attackers to cause memory corruption by providing invalid userspace addresses to the MCDM IOCTL interface. This affects syst...

Nov 4, 2025
CVE-2025-59933
7.8

CVE-2025-59933 is a buffer read overflow vulnerability in libvips when compiled with PDF support via poppler. It allows attackers to cause denial of s...

Sep 29, 2025
CVE-2025-49659
7.8

CVE-2025-49659 is a buffer over-read vulnerability in Windows TDX.sys that allows an authenticated attacker to read beyond allocated memory boundaries...

Jul 8, 2025
CVE-2025-47973
7.8

A buffer over-read vulnerability in Virtual Hard Disk (VHDX) handling allows local attackers to read beyond allocated memory boundaries. This can lead...

Jul 8, 2025
CVE-2025-47971
7.8

A buffer over-read vulnerability in Virtual Hard Disk (VHDX) handling allows local attackers to read beyond allocated memory boundaries. This can lead...

Jul 8, 2025
CVE-2025-21421
7.8

This vulnerability allows memory corruption when processing escape codes in a Qualcomm API, potentially leading to arbitrary code execution. It affect...

Apr 7, 2025
CVE-2024-45561
7.8

This vulnerability allows memory corruption when handling IOCTL calls from user-space to set latency levels in Qualcomm components. Attackers could po...

Feb 3, 2025
CVE-2025-21271
7.8

This vulnerability in the Windows Cloud Files Mini Filter Driver allows attackers to gain SYSTEM-level privileges on affected systems. It affects Wind...

Jan 14, 2025
CVE-2024-45546
7.8

This vulnerability allows memory corruption when processing FIPS encryption/decryption IOCTL calls from user-space in Qualcomm components. Attackers c...

Jan 6, 2025
CVE-2024-45548
7.8

This vulnerability allows attackers to cause memory corruption through a specific IOCTL call related to FIPS encryption/decryption validation. It affe...

Jan 6, 2025
CVE-2024-49088
7.8

This vulnerability in the Windows Common Log File System (CLFS) driver allows an authenticated attacker to gain SYSTEM-level privileges by exploiting ...

Dec 12, 2024
CVE-2024-49031
7.8

This vulnerability allows remote code execution through specially crafted Office graphics files. Attackers can exploit it by tricking users into openi...

Nov 12, 2024
CVE-2024-38250
7.8

This Windows Graphics Component vulnerability allows an attacker to gain SYSTEM-level privileges on affected systems by exploiting a buffer overflow c...

Sep 10, 2024
CVE-2024-38127
7.8

This vulnerability allows an authenticated attacker to execute arbitrary code with elevated privileges on Windows Hyper-V hosts. It affects systems ru...

Aug 13, 2024
CVE-2024-30079
7.8

This vulnerability allows an authenticated attacker to elevate privileges on a Windows system by exploiting a flaw in the Remote Access Connection Man...

Jul 9, 2024
CVE-2023-33115
7.8

This CVE describes a memory corruption vulnerability in Qualcomm's trusted execution environment when processing buffer initialization for certain rep...

Apr 1, 2024

About CWE-126 (CWE-126)

Our database tracks 152 CVEs classified as CWE-126, with 4 rated critical and 111 rated high severity. The average CVSS score for CWE-126 vulnerabilities is 7.3.

External reference: View CWE-126 on MITRE CWE →

Monitor CWE-126 Vulnerabilities

Get alerted when new CWE-126 CVEs affect your infrastructure.

Start Monitoring Free