CWE-126: CWE-126
Yearly Trend
Top Affected Vendors
All CWE-126 CVEs (152)
This vulnerability allows attackers to cause a denial of service (DoS) on Windows systems by exploiting improper handling of extended negotiation in c...
Jul 11, 2023This vulnerability allows an attacker to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN firmware by sending specially crafted bea...
Jun 6, 2023This vulnerability allows attackers to cause a denial-of-service (DoS) condition in WLAN firmware by sending specially crafted Fast Transition (FT) In...
Jun 6, 2023This vulnerability in Windows NFS Portmapper allows attackers to disclose sensitive information from memory. It affects Windows systems running NFS se...
May 9, 2023This vulnerability in Microsoft PostScript and PCL6 Class Printer Drivers allows an attacker to read sensitive information from kernel memory. It affe...
Mar 14, 2023This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN firmware by sending specially crafted secur...
Mar 10, 2023This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN chipsets by sending specially crafted packe...
Mar 10, 2023This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected wireless devices by sending specially crafted management ...
Feb 12, 2023CVE-2022-22519 is a buffer over-read vulnerability in CODESYS Control runtime system webserver that allows remote, unauthenticated attackers to crash ...
Apr 7, 2022This vulnerability in Awesome Miner allows unprivileged users to read and write kernel memory and Model-Specific Registers (MSRs) due to an insecure d...
Nov 18, 2025This vulnerability in Microsoft Windows Admin Center allows an authenticated attacker to read sensitive information from the application's memory. It ...
Sep 10, 2024A heap-based buffer over-read vulnerability in the X.org server's ProcXIPassiveGrabDevice() function allows attackers to cause memory leaks and segmen...
Apr 4, 2024A buffer over-read and off-by-one error vulnerability in RTI Connext Professional Core Libraries allows attackers to read beyond allocated memory boun...
Sep 23, 2025This vulnerability allows a denial-of-service attack when loading Trusted Application (TA) ELF files on Qualcomm chipsets. It affects devices using Qu...
Jul 1, 2024CVE-2022-1534 is a buffer over-read vulnerability in libmobi's parse_rawml.c that allows reading memory beyond allocated buffers. This can lead to inf...
Apr 29, 2022This vulnerability allows information disclosure through improper handling of IOCTL calls in Qualcomm trusted execution environments. Attackers can po...
Jan 6, 2025This vulnerability allows attackers to access sensitive information from memory when parsing dts header atoms in video files. It affects devices using...
May 6, 2024This CVE describes a memory corruption vulnerability in Qualcomm's camera-kernel driver due to improper bounds checking during command handling. An at...
May 6, 2025This CVE describes an information disclosure vulnerability in Qualcomm mailbox write API where processing oversized messages can leak sensitive data. ...
Jan 6, 2025This vulnerability allows an attacker to cause a temporary denial-of-service (DoS) condition by sending specially crafted WLAN management frames conta...
Jan 7, 2026A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read beyond allocated memory bou...
Sep 9, 2025A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read sensitive memory contents o...
Sep 9, 2025A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read beyond allocated memory bou...
Sep 9, 2025A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read beyond allocated memory bou...
Apr 8, 2025A buffer over-read vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to read beyond allocated memory bou...
Apr 8, 2025A heap buffer over-read vulnerability exists in libsoup's sniff_unknown() function, which could allow attackers to read sensitive memory contents or c...
Apr 3, 2025This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by tricking users into vis...
Oct 17, 2024This vulnerability allows information disclosure when handling beacon probe frames during scan entry generation on client devices. It affects devices ...
Aug 5, 2024This vulnerability allows information disclosure when handling Multi-link Information Elements in Wi-Fi beacon frames. It affects devices with Qualcom...
Jul 1, 2024This CVE describes an information disclosure vulnerability in Qualcomm firmware that leaks sensitive data when processing firmware events. It affects ...
Jan 7, 2026This vulnerability allows information disclosure when processing messages from clients with invalid payloads. It affects systems running Qualcomm soft...
Nov 4, 2025This vulnerability allows information disclosure through the diagHal interface when registering commands from clients. It affects Qualcomm devices usi...
Nov 4, 2025This vulnerability in Qualcomm video drivers allows attackers to read sensitive information from kernel memory while processing batch commands. It aff...
Oct 9, 2025This CVE-2025-27030 vulnerability allows unauthorized information disclosure when calibration data is invoked from user space to update firmware size....
Sep 24, 2025CVE-2024-38416 is an information disclosure vulnerability in Qualcomm audio components that allows attackers to access sensitive memory contents durin...
Feb 3, 2025This vulnerability allows unauthorized access to mailbox data through the mailbox read API, potentially exposing sensitive information. It affects Qua...
Jan 6, 2025A buffer over-read vulnerability in PostgreSQL's GB18030 encoding validation allows attackers to cause temporary denial of service by triggering proce...
May 8, 2025A vulnerability in Wireshark's RF4CE Profile protocol dissector causes crashes when processing malicious network packets, leading to denial of service...
Feb 25, 2026This vulnerability allows an attacker to cause a temporary denial of service (DoS) by sending specially crafted video packets to vulnerable systems. I...
Jan 7, 2026This CVE describes a buffer over-read vulnerability in Windows Storage Management Provider that allows an authorized attacker to read beyond allocated...
Oct 14, 2025This vulnerability allows an attacker to cause a temporary denial of service (DoS) by sending specially crafted video packets to affected Qualcomm dev...
Oct 9, 2025This vulnerability is a buffer over-read in the Storage Port Driver that allows an authenticated attacker to read beyond allocated memory boundaries, ...
Jul 8, 2025This CVE describes a buffer over-read vulnerability in Windows NTFS that allows a local attacker to read beyond allocated memory boundaries. This coul...
Mar 11, 2025This vulnerability allows a denial-of-service (DoS) condition in Qualcomm's GVM (Guest Virtual Machine) when it sends a specific message type to the V...
Jan 6, 2025A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can cause an out-of-bounds read when receiving malformed ICMPv6 packet...
Oct 10, 2025A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing allows out-of-bounds reads when receiving IPv6 packets with incorrect payload...
Oct 10, 2025PerfreeBlog v4.0.11 contains an arbitrary file read vulnerability in the validThemeFilePath function that allows attackers to read sensitive files on ...
Oct 24, 2025This vulnerability in NetX Duo's IPv4 packet handling allows an attacker to read 4 bytes of memory beyond allocated boundaries when processing unicast...
Oct 17, 2025This vulnerability in NetX Duo (part of Eclipse ThreadX) allows attackers to read two bytes beyond allocated memory boundaries due to an incorrect bou...
Oct 15, 2025This vulnerability in NGINX's ngx_http_mp4_module allows attackers to cause memory over-read and worker process termination by uploading specially cra...
Aug 14, 2024About CWE-126 (CWE-126)
Our database tracks 152 CVEs classified as CWE-126, with 4 rated critical and 111 rated high severity. The average CVSS score for CWE-126 vulnerabilities is 7.3.
External reference: View CWE-126 on MITRE CWE →
Monitor CWE-126 Vulnerabilities
Get alerted when new CWE-126 CVEs affect your infrastructure.
Start Monitoring Free