CWE-127: Buffer Under-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations prior to the targeted buffer.
8 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-10395 — net: lib: http_server: Buffer Under-read
- CVE-2025-20359 — Multiple Cisco Products Snort 3 MIME Information Disclosure or Denial of Service Vulnerability
- CVE-2025-32050 — Libsoup: integer overflow in append_param_quoted
- CVE-2026-45683 — OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure
- CVE-2026-5928 — Potential buffer under-read in ungetwc
Recently published
- CVE-2026-45683 — OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure
- CVE-2026-5928 — Potential buffer under-read in ungetwc
- CVE-2025-20359 — Multiple Cisco Products Snort 3 MIME Information Disclosure or Denial of Service Vulnerability
- CVE-2025-32050 — Libsoup: integer overflow in append_param_quoted
- CVE-2024-10395 — net: lib: http_server: Buffer Under-read