Threats Tagged 'cwe-126'
View all threats tagged with 'cwe-126'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-126'
Click on any threat for detailed analysis and mitigation recommendations
0 Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue. Join the discussion | CVE Database V5 | 09/23/2026, 12:24:55 UTC Added: 09/23/2026, 12:48:27 UTC |
CVE-2026-25294 is a high-severity vulnerability in Qualcomm Snapdragon products involving a buffer over-read (CWE-126) that causes a transient denial of service (DoS) during frame parsing in channel usage. It does not impact confidentiality or integrity but results in availability disruption. The issue affects multiple specific Snapdragon versions. No patch information is provided, and no known exploits are reported in the wild. Join the discussion | CVE Database V5 | 09/17/2026, 04:11:54 UTC Added: 09/17/2026, 04:32:13 UTC |
CVE-2026-25284 is a high-severity buffer over-read vulnerability in Qualcomm Snapdragon products WSA8840 and WSA8845. It involves information disclosure caused by reuse of a pointer after it has been deallocated. The flaw can lead to unauthorized reading of memory, potentially exposing sensitive data. No known exploits are reported in the wild. The vulnerability requires local privileges and has low attack complexity without user interaction. Confidentiality impact is high, integrity is not affected, and availability impact is low. Join the discussion | CVE Database V5 | 09/17/2026, 04:11:50 UTC Added: 09/17/2026, 04:32:13 UTC |
CVE-2026-25275 is a high-severity vulnerability in Qualcomm Snapdragon products caused by a buffer over-read (CWE-126) when processing authentication frames with invalid FILS information element header lengths. This flaw can cause a transient denial of service (DoS) condition. The vulnerability affects a wide range of specific Qualcomm Snapdragon versions. No information about available patches or vendor advisories is provided. Join the discussion | CVE Database V5 | 09/17/2026, 04:11:36 UTC Added: 09/17/2026, 04:32:12 UTC |
CVE-2026-24081 is a high-severity vulnerability in Qualcomm Snapdragon products involving a buffer over-read (CWE-126) that can cause a transient denial of service (DoS). The issue occurs when processing a channel map with insufficient used channels while adaptive frequency hopping is fully enabled. This vulnerability affects numerous specific Qualcomm Snapdragon versions and does not impact confidentiality or integrity but can disrupt availability. Join the discussion | CVE Database V5 | 09/17/2026, 04:11:30 UTC Added: 09/17/2026, 04:32:12 UTC |
CVE-2026-24075 is a high-severity buffer over-read vulnerability in Qualcomm Snapdragon devices. It occurs due to improper synchronization and race conditions when multiple threads issue concurrent IOCTL requests to the device control handler, leading to memory corruption. This flaw affects specific Snapdragon hardware versions and can result in high impact on confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 09/17/2026, 04:11:28 UTC Added: 09/17/2026, 04:32:12 UTC |
0 A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful exploitation may allow a remote unauthenticated attacker to disclose and modify VPN configuration information. Join the discussion | CVE Database V5 | 09/10/2026, 20:12:43 UTC Added: 09/10/2026, 20:32:31 UTC |
0 Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:19:14 UTC Added: 09/08/2026, 17:27:17 UTC |
0 Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:19:13 UTC Added: 09/08/2026, 17:27:17 UTC |
0 Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:56 UTC Added: 09/08/2026, 17:27:13 UTC |
Showing 1 to 10 of 198 results