CWE-126

Total CVEs
319
Vulnerabilities
Avg CVSS v3
6.8
Medium
Avg CVSS v2
5.3
Medium
Latest CVE
2025
Most Recent

Severity Distribution

Critical 12
3.8%
High 181
56.7%
Medium 118
37%
Low 8
2.5%

External References

All CVEs (319)

Page 1 of 14
CVSS:9.8(Critical)

Memory corruption during management frame processing due to mismatch in T2LM info element.

CVSS:9.8(Critical)

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVSS:9.8(Critical)

Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

CVSS:9.8(Critical)

Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00

CVSS:9.8(Critical)

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on...

CVSS:9.8(Critical)

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.

CVSS:9.8(Critical)

In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.

CVSS:9.1(Critical)

Memory corruption while decoding of OTA messages from T3448 IE.

CVSS:9.1(Critical)

Information Disclosure while parsing beacon frame in STA.

CVSS:9.1(Critical)

BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c.

CVSS:9.1(Critical)

Information disclosure in Modem while processing SIB5.

CVSS:9.1(Critical)

Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

CVSS:8.8(High)

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

CVSS:8.8(High)

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVSS:8.8(High)

Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.

CVSS:8.6(High)

A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This ...

CVSS:8.6(High)

A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card ...

CVSS:8.6(High)

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditio...

CVSS:8.6(High)

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controll...

CVSS:8.6(High)

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unaut...

CVSS:8.2(High)

Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.

CVSS:8.2(High)

Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

CVSS:8.2(High)

Information disclosure while parsing the multiple MBSSID IEs from the beacon.

CVSS:8.2(High)

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.