Vulnerabilities (CVE)

Filtered by CWE-126
Total 521 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-67393 1 Microsoft 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more 2026-09-15 N/A 6.5 MEDIUM
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67390 1 Microsoft 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more 2026-09-15 N/A 6.5 MEDIUM
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-73029 1 Microsoft 3 Sql Server 2019, Sql Server 2022, Sql Server 2025 2026-09-15 N/A 6.5 MEDIUM
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-90610 2026-09-15 1.7 LOW 3.3 LOW
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 mitigates this issue. The patch is named afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.
CVE-2026-68851 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-09-14 N/A 5.5 MEDIUM
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-68875 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-09-14 N/A 7.8 HIGH
Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-44185 1 Apache 1 Http Server 2026-09-14 N/A 7.3 HIGH
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-76653 2026-09-11 N/A N/A
A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information.
CVE-2026-58013 2 Gnome, Redhat 2 Glib, Enterprise Linux 2026-09-10 N/A 6.5 MEDIUM
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.
CVE-2026-58012 2 Gnome, Redhat 2 Glib, Enterprise Linux 2026-09-10 N/A 6.5 MEDIUM
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
CVE-2026-58010 2 Gnome, Redhat 2 Glib, Enterprise Linux 2026-09-10 N/A 6.5 MEDIUM
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
CVE-2026-78516 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-09-10 N/A 4.3 MEDIUM
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-53587 2026-09-09 N/A 7.5 HIGH
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. This issue is fixed in versions 1.8.6 and 1.9.5.
CVE-2026-69582 2026-09-09 N/A 7.8 HIGH
Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69626 1 Microsoft 6 365 Apps, Microsoft 365, Office 2016 and 3 more 2026-09-09 N/A 6.5 MEDIUM
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
CVE-2026-81399 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-09-09 N/A 5.5 MEDIUM
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-72974 1 Microsoft 6 365 Apps, Microsoft 365, Office 2016 and 3 more 2026-09-09 N/A 6.5 MEDIUM
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-69610 2026-09-09 N/A 7.0 HIGH
Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-69416 2026-09-08 N/A 5.7 MEDIUM
Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.
CVE-2026-83949 1 Microsoft 5 365 Apps, Office 2019, Office 2021 and 2 more 2026-09-08 N/A 5.5 MEDIUM
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.