CWE-126
CVEs classified under CWE-126, newest first.
89 CVEsRSS
CVE-2026-76885Low· 3.1Buffer Over-read in Wireshark
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76884Low· 3.1PoCBuffer Over-read in Wireshark
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-69550Medium· 6.5Windows App for Mac Information Disclosure Vulnerability
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-65936NoneA malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
CVE-2026-65933NoneA malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
CVE-2026-18024Medium· 4.3Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instanc…
CVE-2026-14678Medium· 4.3Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQ…
CVE-2026-62746Medium· 5.5Win32k Information Disclosure Vulnerability
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-68819Medium· 5.9Windows Network File System Denial of Service Vulnerability
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
CVE-2026-62793Medium· 5.5Windows NTFS Information Disclosure Vulnerability
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62730Medium· 5.5Windows Wired AutoConfig Service Information Disclosure Vulnerability
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
CVE-2026-64905High· 7.8Microsoft Office Word Remote Code Execution Vulnerability
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-65794Medium· 6.5Windows SMB Client Information Disclosure Vulnerability
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61350Medium· 4.6Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-61347Medium· 5.5Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CVE-2026-66312Medium· 6.5Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-50372High· 7.0Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
CVE-2026-50341Medium· 5.5Windows NTFS Information Disclosure Vulnerability
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-50445Medium· 6.5Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50435High· 7.8Windows Overlay Filter Elevation of Privilege Vulnerability
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
CVE-2026-50402High· 7.8PoCNTFS Elevation of Privilege Vulnerability
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50383Medium· 6.1Windows Print Spooler Information Disclosure Vulnerability
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
CVE-2026-50475Medium· 5.5Windows Kernel Information Disclosure Vulnerability
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50485Medium· 4.5Windows Hyper-V Denial of Service Vulnerability
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2026-50504Medium· 6.5Windows Remote Desktop Client Information Disclosure Vulnerability
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-55036High· 7.8Microsoft Excel Remote Code Execution Vulnerability
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-50468Medium· 6.5Microsoft SQL Server Information Disclosure Vulnerability
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-57968High· 7.8Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
CVE-2026-59840Medium· 4.3A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through…
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through…
CVE-2025-43892Medium· 4.3A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a po…
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a po…