CWE-126: CWE-126

151
Total CVEs
4
Critical
110
High
7.3
Avg CVSS

Yearly Trend

2026
8
2025
65
2024
37
2023
32
2022
7

Top Affected Vendors

1 Qualcomm 86
2 Microsoft 34
3 Fedoraproject 3
4 Vim 3
5 Wazuh 2
6 Eclipse 2
7 Codesys 2
8 Cisco 2
9 Libmobi Project 2
10 Apple 2

All CWE-126 CVEs (151)

CVE-2023-36904
7.8

This vulnerability in the Windows Cloud Files Mini Filter Driver allows an authenticated attacker to gain SYSTEM-level privileges by exploiting a buff...

Aug 8, 2023
CVE-2023-28541
7.8

This vulnerability allows memory corruption in Qualcomm data modem firmware when processing DMA buffer release events for CFR data. Attackers could po...

Jul 4, 2023
CVE-2022-2175
7.8

CVE-2022-2175 is a buffer over-read vulnerability in Vim text editor versions prior to 8.2. This allows attackers to read memory beyond allocated buff...

Jun 23, 2022
CVE-2022-2124
7.8

CVE-2022-2124 is a buffer over-read vulnerability in Vim text editor that allows reading beyond allocated memory boundaries. This affects users runnin...

Jun 19, 2022
CVE-2022-1629
7.8

CVE-2022-1629 is a buffer over-read vulnerability in Vim's find_next_quote function that could allow attackers to crash the application, modify memory...

May 10, 2022
CVE-2024-12011
7.6

CVE-2024-12011 is a buffer over-read vulnerability in the 130.8005 TCP/IP Gateway firmware that allows unauthenticated attackers to leak authenticatio...

Feb 13, 2025
CVE-2026-20846
7.5

This vulnerability is a buffer over-read in Windows GDI+ that allows an unauthorized attacker to cause a denial of service over a network. It affects ...

Feb 10, 2026
CVE-2025-66692
7.5

A buffer over-read vulnerability in Trust Wallet Core's PublicKey::verify() method allows attackers to cause Denial of Service (DoS) by sending crafte...

Jan 20, 2026
CVE-2025-60003
7.5

A buffer over-read vulnerability in Juniper's routing protocol daemon (rpd) allows unauthenticated attackers to cause denial-of-service by sending spe...

Jan 15, 2026
CVE-2025-62792
7.5

A buffer over-read vulnerability in Wazuh allows compromised agents or attackers who can send crafted messages to the Wazuh manager to read beyond all...

Oct 29, 2025
CVE-2025-62787
7.5

A buffer over-read vulnerability in Wazuh's DecodeWinevt() function allows compromised agents to trigger read operations beyond allocated buffer bound...

Oct 29, 2025
CVE-2025-47318
7.5

This vulnerability allows attackers to cause a denial of service (DoS) condition by sending specially crafted EPTM test control messages. It affects s...

Sep 24, 2025
CVE-2025-27065
7.5

This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending a specially crafted frame with a malformed shared-key descriptor t...

Aug 6, 2025
CVE-2025-21446
7.5

This vulnerability allows a denial-of-service (DoS) condition in Qualcomm wireless LAN (WLAN) chipsets when processing vendor-specific information ele...

Jul 8, 2025
CVE-2025-27029
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) condition by sending specially crafted tone measurement responses that exceed b...

Jun 3, 2025
CVE-2025-21463
7.5

This vulnerability allows an attacker to cause a Denial of Service (DoS) condition by sending specially crafted beacon frames containing EHT operation...

Jun 3, 2025
CVE-2024-52878
7.5

This CVE describes a buffer over-read vulnerability in InsydeH2O UEFI firmware's VariableRuntimeDxe driver. Attackers could exploit this to read sensi...

May 15, 2025
CVE-2025-21459
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) condition by sending specially crafted ML IE (Management Information Element) p...

May 6, 2025
CVE-2024-49847
7.5

This vulnerability allows attackers to cause a denial-of-service condition in Qualcomm devices by sending specially crafted registration acceptance OT...

May 6, 2025
CVE-2025-21429
7.5

This vulnerability allows memory corruption during Wi-Fi connection establishment between a station (STA) and access point (AP) when initiating an ADD...

Apr 7, 2025
CVE-2025-21434
7.5

This vulnerability allows a denial-of-service (DoS) condition in Wi-Fi systems when parsing EHT (Extremely High Throughput) operation or capability in...

Apr 7, 2025
CVE-2024-38404
7.5

This vulnerability in Qualcomm modems allows a transient denial-of-service (DoS) condition when the device receives a registration accept message with...

Feb 3, 2025
CVE-2025-21277
EPSS 20.1% 7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service by sending specially crafted packets to vulnerabl...

Jan 14, 2025
CVE-2024-45558
7.5

This vulnerability in Qualcomm Wi-Fi drivers allows attackers to cause a denial-of-service (DoS) condition by sending specially crafted packets. The d...

Jan 6, 2025
CVE-2024-38405
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) condition by sending specially crafted Radio Resource Control (RRC) messages co...

Nov 4, 2024
CVE-2024-33070
7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon or probe response frames contai...

Oct 7, 2024
CVE-2024-33049
7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon frames with specific Extension ...

Oct 7, 2024
CVE-2024-9029
7.5

A buffer over-read vulnerability in FreeImage library allows attackers to cause denial of service by processing a specially crafted image. This affect...

Sep 27, 2024
CVE-2024-33048
7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted beacon or probe response frames to aff...

Sep 2, 2024
CVE-2024-33051
7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition in affected Wi-Fi systems by sending specially crafted beacon frame...

Sep 2, 2024
CVE-2024-23358
7.5

This vulnerability in Qualcomm modems allows a transient denial-of-service (DoS) condition when the device receives a registration accept OTA (Over-Th...

Sep 2, 2024
CVE-2024-33026
7.5

This vulnerability allows an attacker to cause a denial-of-service condition in affected Qualcomm Wi-Fi components by sending specially crafted probe ...

Aug 5, 2024
CVE-2024-33020
7.5

This vulnerability in Qualcomm chipsets allows attackers to cause a denial-of-service condition by sending specially crafted TID-to-link mapping IE el...

Aug 5, 2024
CVE-2024-33018
7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition by sending specially crafted TID-to-link mapping action frames to a...

Aug 5, 2024
CVE-2024-33012
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in Wi-Fi systems by sending specially crafted beacon frames with malf...

Aug 5, 2024
CVE-2024-33014
7.5

This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending specially crafted beacon or probe response frames containing malfo...

Aug 5, 2024
CVE-2024-21479
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) condition by exploiting a buffer over-read (CWE-126) in Apple Lossless Audio Co...

Aug 5, 2024
CVE-2023-43536
7.5

This vulnerability in Qualcomm components allows a denial-of-service (DoS) attack when parsing files with specific length characteristics. It affects ...

Feb 6, 2024
CVE-2023-33116
7.5

This vulnerability in Qualcomm's WIN WLAN driver allows a denial-of-service (DoS) attack when parsing specific wireless network management frames. Att...

Jan 2, 2024
CVE-2023-33040
7.5

This vulnerability allows a remote attacker to cause a denial-of-service (DoS) condition in Qualcomm's Data Modem during DTLS handshake processing. It...

Jan 2, 2024
CVE-2023-35643
7.5

This vulnerability in the DHCP Server Service allows an attacker to read sensitive information from memory, potentially exposing credentials or other ...

Dec 12, 2023
CVE-2023-35638
7.5

This vulnerability in the Windows DHCP Server service allows an attacker to send specially crafted packets that cause a denial of service (DoS) condit...

Dec 12, 2023
CVE-2023-33097
7.5

This vulnerability allows attackers to cause a temporary denial-of-service (DoS) in WLAN firmware by sending specially crafted Fast Transition Managem...

Dec 5, 2023
CVE-2023-33081
7.5

CVE-2023-33081 is a buffer overflow vulnerability in Qualcomm chipsets that occurs when processing Target Wake Time (TWT) frame parameters in over-the...

Dec 5, 2023
CVE-2023-33048
7.5

CVE-2023-33048 is a buffer overflow vulnerability in Qualcomm WLAN firmware that allows attackers to cause a denial-of-service (DoS) condition by send...

Nov 7, 2023
CVE-2023-33061
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected devices by sending specially crafted WLAN beacon or probe...

Nov 7, 2023
CVE-2023-33026
7.5

This vulnerability allows attackers to cause a temporary denial-of-service (DoS) in affected Wi-Fi devices by sending specially crafted NAN (Neighborh...

Oct 3, 2023
CVE-2023-33015
7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition in Qualcomm WLAN firmware by sending specially crafted beacon frame...

Sep 5, 2023
CVE-2023-38172
7.5

This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service by sending specially crafted packets. Systems run...

Aug 8, 2023
CVE-2023-35330
7.5

This vulnerability allows attackers to cause a denial of service (DoS) on Windows systems by exploiting improper handling of extended negotiation in c...

Jul 11, 2023

About CWE-126 (CWE-126)

Our database tracks 151 CVEs classified as CWE-126, with 4 rated critical and 110 rated high severity. The average CVSS score for CWE-126 vulnerabilities is 7.3.

External reference: View CWE-126 on MITRE CWE →

Monitor CWE-126 Vulnerabilities

Get alerted when new CWE-126 CVEs affect your infrastructure.

Start Monitoring Free