The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Volume of CVEs assigned to CWE-126 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
476 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-49285HIGH Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Messag | Dec 4, 2023 | 7.5 | 69 | NO | NO |
CVE-2017-7668HIGH The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input str | Jun 20, 2017 | 7.5 | 56 | NO | NO |
CVE-2017-7679CRITICAL In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header. | Jun 20, 2017 | 9.8 | 52 | NO | NO |
CVE-2024-20290HIGH A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This | Feb 7, 2024 | 7.5 | 42 | NO | NO |
CVE-2025-21277HIGH Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | Jan 14, 2025 | 7.5 | 40 | NO | NO |
CVE-2023-36397CRITICAL Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | Nov 14, 2023 | 9.8 | 40 | NO | NO |
CVE-2026-58010HIGH A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the | Jun 30, 2026 | 8.2 | 38 | NO | NO |
CVE-2024-38071HIGH Windows Remote Desktop Licensing Service Denial of Service Vulnerability | Jul 9, 2024 | 7.5 | 37 | NO | NO |
CVE-2026-5260HIGH A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, | May 26, 2026 | 8.2 | 36 | NO | NO |
CVE-2009-2495MEDIUM The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not pro | Jul 29, 2009 | 6.5 | 36 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.