Vulnerabilities (CVE)

Filtered by CWE-126
Total 213 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-1010220 1 Tcpdump 1 Tcpdump 2023-11-07 4.3 MEDIUM 3.3 LOW
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.
CVE-2017-7679 1 Apache 1 Http Server 2023-11-07 7.5 HIGH 9.8 CRITICAL
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
CVE-2017-7668 6 Apache, Apple, Debian and 3 more 13 Http Server, Mac Os X, Debian Linux and 10 more 2023-11-07 5.0 MEDIUM 7.5 HIGH
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.
CVE-2023-4758 1 Gpac 1 Gpac 2023-09-06 N/A 5.5 MEDIUM
Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV.
CVE-2023-3649 1 Wireshark 1 Wireshark 2023-07-25 N/A 5.5 MEDIUM
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file
CVE-2023-23571 1 Milesight 2 Ur32l, Ur32l Firmware 2023-07-17 N/A 7.5 HIGH
An access violation vulnerability exists in the eventcore functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to denial of service. An attacker can send a network request to trigger this vulnerability.
CVE-2022-3178 1 Gpac 1 Gpac 2023-06-29 N/A 7.8 HIGH
Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-32141 1 Codesys 2 Plcwinnt, Runtime Toolkit 2023-06-29 4.0 MEDIUM 6.5 MEDIUM
Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an invalid offset, which can cause an internal buffer over-read, resulting in a denial-of-service condition. User interaction is not required.
CVE-2022-4435 1 Lenovo 2 Thinkpad X13s, Thinkpad X13s Firmware 2023-05-15 N/A 4.4 MEDIUM
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
CVE-2022-4433 1 Lenovo 2 Thinkpad X13s, Thinkpad X13s Firmware 2023-05-15 N/A 4.4 MEDIUM
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
CVE-2022-4432 1 Lenovo 2 Thinkpad X13s, Thinkpad X13s Firmware 2023-05-15 N/A 4.4 MEDIUM
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
CVE-2023-24513 5 Amazon, Arista, Equinix and 2 more 6 Aws Marketplace, Cloudeos, Dca-200-veos and 3 more 2023-04-24 N/A 7.5 HIGH
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
CVE-2023-0817 1 Gpac 1 Gpac 2023-02-22 N/A 7.8 HIGH
Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.
CVE-2023-0396 1 Zephyrproject 1 Zephyr 2023-02-03 N/A 6.8 MEDIUM
A malicious / defective bluetooth controller can cause buffer overreads in the most functions that process HCI command responses.
CVE-2022-4434 1 Lenovo 2 Thinkpad X13s, Thinkpad X13s Firmware 2023-02-02 N/A 4.4 MEDIUM
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.
CVE-2020-35511 2 Debian, Libpng 2 Debian Linux, Pngcheck 2023-02-02 N/A 7.8 HIGH
A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.
CVE-2022-44445 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-01-10 N/A 5.5 MEDIUM
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
CVE-2022-44443 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-01-10 N/A 5.5 MEDIUM
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
CVE-2022-39132 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2022-12-07 N/A 5.5 MEDIUM
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
CVE-2022-39130 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2022-12-07 N/A 5.5 MEDIUM
In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.