Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-126

Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

476
Assigned CVEs
80th
Commonality Rank
6.9
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-126 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2009
16 years ago
Most Recent CVE
Jul 20, 2026
4 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

476 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-49285HIGH
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Messag
Dec 4, 20237.569NONO
CVE-2017-7668HIGH
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input str
Jun 20, 20177.556NONO
CVE-2017-7679CRITICAL
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
Jun 20, 20179.852NONO
CVE-2024-20290HIGH
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This
Feb 7, 20247.542NONO
CVE-2025-21277HIGH
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Jan 14, 20257.540NONO
CVE-2023-36397CRITICAL
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Nov 14, 20239.840NONO
CVE-2026-58010HIGH
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the
Jun 30, 20268.238NONO
CVE-2024-38071HIGH
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Jul 9, 20247.537NONO
CVE-2026-5260HIGH
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token,
May 26, 20268.236NONO
CVE-2009-2495MEDIUM
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not pro
Jul 29, 20096.536NONO
View all 476 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
23%
19%
5.0-5.9
11%
16%
6.0-6.9
50%
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products