Filtered by CWE-126
Total 414 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-21428 1 Qualcomm 138 9206 Lte Modem, 9206 Lte Modem Firmware, Apq8017 and 135 more 2025-10-06 7.5 High
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
CVE-2024-23364 1 Qualcomm 359 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 356 more 2025-10-03 7.5 High
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
CVE-2024-23358 1 Qualcomm 107 205 Mobile Platform, 205 Mobile Platform Firmware, Apq8017 and 104 more 2025-10-03 7.5 High
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
CVE-2024-23359 1 Qualcomm 324 205 Mobile Platform, 205 Mobile Platform Firmware, 315 5g Iot Modem and 321 more 2025-10-03 8.2 High
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2025-4582 1 Rti 1 Connext Professional 2025-10-02 7.1 High
Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6.1.0 before 6.1.2.26, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.4a before 5.2.*.
CVE-2025-47328 1 Qualcomm 135 Fastconnect 7800, Fastconnect 7800 Firmware, Immersive Home 3210 Platform and 132 more 2025-09-25 7.5 High
Transient DOS while processing power control requests with invalid antenna or stream values.
CVE-2025-47326 1 Qualcomm 241 Ar8035, Ar8035 Firmware, Csr8811 and 238 more 2025-09-25 7.5 High
Transient DOS while handling command data during power control processing.
CVE-2025-27057 1 Qualcomm 422 Ar8035, Ar8035 Firmware, Csr8811 and 419 more 2025-09-25 7.5 High
Transient DOS while handling beacon frames with invalid IE header length.
CVE-2025-27030 1 Qualcomm 83 C-v2x 9150, C-v2x 9150 Firmware, Qam8295p and 80 more 2025-09-25 6.1 Medium
information disclosure while invoking calibration data from user space to update firmware size.
CVE-2025-27033 1 Qualcomm 65 Qca6698aq, Qca6698aq Firmware, Qcm5430 and 62 more 2025-09-25 6.1 Medium
Information disclosure while running video usecase having rogue firmware.
CVE-2025-27036 1 Qualcomm 43 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 40 more 2025-09-25 6.1 Medium
Information disclosure when Video engine escape input data is less than expected minimum size.
CVE-2025-47317 1 Qualcomm 107 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 104 more 2025-09-25 7.8 High
Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
CVE-2024-12975 2025-09-16 N/A
A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.
CVE-2025-32704 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2025-09-10 8.4 High
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29956 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-09-10 5.4 Medium
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
CVE-2025-21176 4 Apple, Linux, Microsoft and 1 more 22 Macos, Linux Kernel, .net and 19 more 2025-09-09 8.8 High
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
CVE-2025-21277 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-09-09 7.5 High
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-21271 1 Microsoft 5 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 2 more 2025-09-09 7.8 High
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-36855 1 Microsoft 1 .net 2025-09-09 8.8 High
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. This issue affects EOL ASP.NET 6.0.0 <= 6.0.36 as represented in this CVE, as well as 8.0.0 <= 8.0.11 & <= 9.0.0 as represented in CVE-2025-21176. Additionally, if you've deployed self-contained applications https://docs.microsoft.com/dotnet/core/deploying/#self-contained-deployments-scd  targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.
CVE-2024-30039 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-08-27 5.5 Medium
Windows Remote Access Connection Manager Information Disclosure Vulnerability