Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-126

MITRE ↗

CWE-126

33
HIGH
59
MEDIUM
5
LOW
100 CVEs · Page 1/2
8.2
CVE-2026-5260

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key excha

8.1
CVE-2026-25646

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)

7.9
CVE-2026-28364

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re

7.8
CVE-2025-59600

Memory Corruption when adding user-supplied data without checking available buffer space.

7.8
CVE-2025-47390

Memory corruption while preprocessing IOCTL request in JPEG driver.

7.8
CVE-2026-21371

Memory Corruption when retrieving output buffer with insufficient size validation.

7.8
CVE-2026-21373

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

7.8
CVE-2026-21374

Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validatio

7.8
CVE-2026-21375

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

7.8
CVE-2026-21376

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor

7.8
CVE-2026-21378

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor

7.8
CVE-2026-26184

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-42828

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-21379

Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.

7.8
CVE-2026-50402

Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50435

Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-55036

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-57968

Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-64905

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.6
CVE-2026-21367

Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.

7.6
CVE-2026-21381

Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware

7.5
CVE-2025-60003

A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved

7.5
CVE-2025-66692

A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attacke

7.5
CVE-2026-20846

Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

7.5
CVE-2026-34059

Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are

7.5
CVE-2026-41992

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shar

7.5
CVE-2026-53587

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing

7.4
CVE-2026-4371

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside th

7.4
CVE-2026-25288

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

7.3
CVE-2026-44185

Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server T

7.1
CVE-2025-47400

Cryptographic issue while copying data to a destination buffer without validating its size.

7.1
CVE-2026-37532

AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_re

7.0
CVE-2026-50372

Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.

6.6
CVE-2026-26282

NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an ou

6.5
CVE-2025-47395

Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.

6.5
CVE-2025-47402

Transient DOS when processing a received frame with an excessively large authentication information element.

6.5
CVE-2026-2394

Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects C

6.5
CVE-2026-26155

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

6.5
CVE-2026-6238

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail t

6.5
CVE-2025-47401

Transient DOS when processing target power rate tables during channel configuration.

6.5
CVE-2025-47403

Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireles

6.5
CVE-2026-58010

A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-seriali

6.5
CVE-2026-58012

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW`

6.5
CVE-2026-58013

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when

6.5
CVE-2026-50445

Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-50468

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-50504

Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-63091

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r

6.5
CVE-2026-55970

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a

6.5
CVE-2026-66312

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Frequently Asked Questions

What is CWE-126?

CWE-126 (CWE-126) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-126?

There are 100 CVE records associated with CWE-126 in our database. Of these, 0 are critical severity, 33 are high severity, and 59 are medium severity.

How can I protect against CWE-126 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-126 using AI-powered security agents.

Detect CWE-126 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-126 vulnerabilities across your infrastructure.

Get Started