CWE-126: CWE-126

152
Total CVEs
4
Critical
111
High
7.3
Avg CVSS

Yearly Trend

2026
8
2025
65
2024
37
2023
32
2022
7

Top Affected Vendors

1 Qualcomm 86
2 Microsoft 34
3 Fedoraproject 3
4 Cisco 3
5 Vim 3
6 Wazuh 2
7 Eclipse 2
8 Codesys 2
9 Libmobi Project 2
10 Apple 2

All CWE-126 CVEs (152)

CVE-2023-35330
7.5

This vulnerability allows attackers to cause a denial of service (DoS) on Windows systems by exploiting improper handling of extended negotiation in c...

Jul 11, 2023
CVE-2023-21658
7.5

This vulnerability allows an attacker to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN firmware by sending specially crafted bea...

Jun 6, 2023
CVE-2023-21660
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in WLAN firmware by sending specially crafted Fast Transition (FT) In...

Jun 6, 2023
CVE-2023-24901
7.5

This vulnerability in Windows NFS Portmapper allows attackers to disclose sensitive information from memory. It affects Windows systems running NFS se...

May 9, 2023
CVE-2023-24858
7.5

This vulnerability in Microsoft PostScript and PCL6 Class Printer Drivers allows an attacker to read sensitive information from kernel memory. It affe...

Mar 14, 2023
CVE-2022-33309
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN firmware by sending specially crafted secur...

Mar 10, 2023
CVE-2022-40535
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN chipsets by sending specially crafted packe...

Mar 10, 2023
CVE-2022-33306
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected wireless devices by sending specially crafted management ...

Feb 12, 2023
CVE-2022-22519
7.5

CVE-2022-22519 is a buffer over-read vulnerability in CODESYS Control runtime system webserver that allows remote, unauthenticated attackers to crash ...

Apr 7, 2022
CVE-2025-63602
7.3

This vulnerability in Awesome Miner allows unprivileged users to read and write kernel memory and Model-Specific Registers (MSRs) due to an insecure d...

Nov 18, 2025
CVE-2024-43475
7.3

This vulnerability in Microsoft Windows Admin Center allows an authenticated attacker to read sensitive information from the application's memory. It ...

Sep 10, 2024
CVE-2024-31081
7.3

A heap-based buffer over-read vulnerability in the X.org server's ProcXIPassiveGrabDevice() function allows attackers to cause memory leaks and segmen...

Apr 4, 2024
CVE-2025-4582
7.1

A buffer over-read and off-by-one error vulnerability in RTI Connext Professional Core Libraries allows attackers to read beyond allocated memory boun...

Sep 23, 2025
CVE-2024-21462
7.1

This vulnerability allows a denial-of-service attack when loading Trusted Application (TA) ELF files on Qualcomm chipsets. It affects devices using Qu...

Jul 1, 2024
CVE-2022-1534
7.1

CVE-2022-1534 is a buffer over-read vulnerability in libmobi's parse_rawml.c that allows reading memory beyond allocated buffers. This can lead to inf...

Apr 29, 2022
CVE-2024-33061
6.8

This vulnerability allows information disclosure through improper handling of IOCTL calls in Qualcomm trusted execution environments. Attackers can po...

Jan 6, 2025
CVE-2023-43527
6.8

This vulnerability allows attackers to access sensitive information from memory when parsing dts header atoms in video files. It affects devices using...

May 6, 2024
CVE-2024-45568
6.7

This CVE describes a memory corruption vulnerability in Qualcomm's camera-kernel driver due to improper bounds checking during command handling. An at...

May 6, 2025
CVE-2024-23366
6.6

This CVE describes an information disclosure vulnerability in Qualcomm mailbox write API where processing oversized messages can leak sensitive data. ...

Jan 6, 2025
CVE-2025-47395
6.5

This vulnerability allows an attacker to cause a temporary denial-of-service (DoS) condition by sending specially crafted WLAN management frames conta...

Jan 7, 2026
CVE-2025-53796
6.5

A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read beyond allocated memory bou...

Sep 9, 2025
CVE-2025-53797
6.5

A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory contents o...

Sep 9, 2025
CVE-2025-53798
6.5

A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read beyond allocated memory bou...

Sep 9, 2025
CVE-2025-26672
6.5

A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read beyond allocated memory bou...

Apr 8, 2025
CVE-2025-26664
6.5

A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read beyond allocated memory bou...

Apr 8, 2025
CVE-2025-32052
6.5

A heap buffer over-read vulnerability exists in libsoup's sniff_unknown() function, which could allow attackers to read sensitive memory contents or c...

Apr 3, 2025
CVE-2024-43595
6.5

This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by tricking users into vis...

Oct 17, 2024
CVE-2024-21467
6.5

This vulnerability allows information disclosure when handling beacon probe frames during scan entry generation on client devices. It affects devices ...

Aug 5, 2024
CVE-2024-21457
6.5

This vulnerability allows information disclosure when handling Multi-link Information Elements in Wi-Fi beacon frames. It affects devices with Qualcom...

Jul 1, 2024
CVE-2025-47331
6.1

This CVE describes an information disclosure vulnerability in Qualcomm firmware that leaks sensitive data when processing firmware events. It affects ...

Jan 7, 2026
CVE-2025-47362
6.1

This vulnerability allows information disclosure when processing messages from clients with invalid payloads. It affects systems running Qualcomm soft...

Nov 4, 2025
CVE-2025-27064
6.1

This vulnerability allows information disclosure through the diagHal interface when registering commands from clients. It affects Qualcomm devices usi...

Nov 4, 2025
CVE-2025-27045
6.1

This vulnerability in Qualcomm video drivers allows attackers to read sensitive information from kernel memory while processing batch commands. It aff...

Oct 9, 2025
CVE-2025-27030
6.1

This CVE-2025-27030 vulnerability allows unauthorized information disclosure when calibration data is invoked from user space to update firmware size....

Sep 24, 2025
CVE-2024-38416
6.1

CVE-2024-38416 is an information disclosure vulnerability in Qualcomm audio components that allows attackers to access sensitive memory contents durin...

Feb 3, 2025
CVE-2024-43063
6.1

This vulnerability allows unauthorized access to mailbox data through the mailbox read API, potentially exposing sensitive information. It affects Qua...

Jan 6, 2025
CVE-2025-4207
5.9

A buffer over-read vulnerability in PostgreSQL's GB18030 encoding validation allows attackers to cause temporary denial of service by triggering proce...

May 8, 2025
CVE-2026-3203
5.5

A vulnerability in Wireshark's RF4CE Profile protocol dissector causes crashes when processing malicious network packets, leading to denial of service...

Feb 25, 2026
CVE-2025-47330
5.5

This vulnerability allows an attacker to cause a temporary denial of service (DoS) by sending specially crafted video packets to vulnerable systems. I...

Jan 7, 2026
CVE-2025-55325
5.5

This CVE describes a buffer over-read vulnerability in Windows Storage Management Provider that allows an authorized attacker to read beyond allocated...

Oct 14, 2025
CVE-2025-27041
5.5

This vulnerability allows an attacker to cause a temporary denial of service (DoS) by sending specially crafted video packets to affected Qualcomm dev...

Oct 9, 2025
CVE-2025-49684
5.5

This vulnerability is a buffer over-read in the Storage Port Driver that allows an authenticated attacker to read beyond allocated memory boundaries, ...

Jul 8, 2025
CVE-2025-24992
5.5

This CVE describes a buffer over-read vulnerability in Windows NTFS that allows a local attacker to read beyond allocated memory boundaries. This coul...

Mar 11, 2025
CVE-2024-45559
5.5

This vulnerability allows a denial-of-service (DoS) condition in Qualcomm's GVM (Guest Virtual Machine) when it sends a specific message type to the V...

Jan 6, 2025
CVE-2025-11616
5.4

A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can cause an out-of-bounds read when receiving malformed ICMPv6 packet...

Oct 10, 2025
CVE-2025-11617
5.4

A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing allows out-of-bounds reads when receiving IPv6 packets with incorrect payload...

Oct 10, 2025
CVE-2025-60729
5.3

PerfreeBlog v4.0.11 contains an arbitrary file read vulnerability in the validThemeFilePath function that allows attackers to read sensitive files on ...

Oct 24, 2025
CVE-2025-55093
5.3

This vulnerability in NetX Duo's IPv4 packet handling allows an attacker to read 4 bytes of memory beyond allocated boundaries when processing unicast...

Oct 17, 2025
CVE-2025-55083
5.3

This vulnerability in NetX Duo (part of Eclipse ThreadX) allows attackers to read two bytes beyond allocated memory boundaries due to an incorrect bou...

Oct 15, 2025
CVE-2024-7347
4.7

This vulnerability in NGINX's ngx_http_mp4_module allows attackers to cause memory over-read and worker process termination by uploading specially cra...

Aug 14, 2024

About CWE-126 (CWE-126)

Our database tracks 152 CVEs classified as CWE-126, with 4 rated critical and 111 rated high severity. The average CVSS score for CWE-126 vulnerabilities is 7.3.

External reference: View CWE-126 on MITRE CWE →

Monitor CWE-126 Vulnerabilities

Get alerted when new CWE-126 CVEs affect your infrastructure.

Start Monitoring Free