A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key excha
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re
Memory Corruption when adding user-supplied data without checking available buffer space.
Memory corruption while preprocessing IOCTL request in JPEG driver.
Memory Corruption when retrieving output buffer with insufficient size validation.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validatio
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware
A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved
A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attacke
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are
GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shar
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside th
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server T
Cryptographic issue while copying data to a destination buffer without validating its size.
AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_re
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an ou
Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
Transient DOS when processing a received frame with an excessively large authentication information element.
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects C
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail t
Transient DOS when processing target power rate tables during channel configuration.
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireles
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-seriali
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW`
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r
Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Frequently Asked Questions
What is CWE-126?
CWE-126 (CWE-126) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-126?
There are 100 CVE records associated with CWE-126 in our database. Of these, 0 are critical severity, 33 are high severity, and 59 are medium severity.
How can I protect against CWE-126 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-126 using AI-powered security agents.
Detect CWE-126 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-126 vulnerabilities across your infrastructure.
Get Started