Cyber Resilience

CWE · MITRE source

CWE-126Buffer Over-read

Abstraction: Variant · CVEs in our corpus: 497

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Last updated: 22 August 2026 14:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SA-11 Developer Testing and Evaluation
  • ID.RA-01
  • PR.PS-02
  • PR.PS-06
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-7679 9.19.80.39342017-06-20
CVE-2023-49285 8.88.60.88822023-12-04
CVE-2023-36397 8.59.80.17512023-11-14
CVE-2017-7668 8.17.50.57472017-06-20
CVE-2018-14790 8.09.80.05382018-10-01
CVE-2019-3563 7.69.80.01712019-04-29
CVE-2019-11036 7.69.10.07032019-05-03
CVE-2025-21277 7.67.50.38612025-01-14
CVE-2024-20290 7.57.50.33562024-02-07
CVE-2024-38071 7.57.50.35852024-07-09
CVE-2017-17772 7.29.80.00342024-11-26
CVE-2021-34584 7.19.10.01112021-10-26
CVE-2023-51773 7.19.10.01052024-02-29
CVE-2025-21176 7.08.80.02352025-01-14
CVE-2024-38373 6.99.60.00622024-06-24
CVE-2025-12106 6.99.10.00542025-12-01
CVE-2009-2495 6.86.50.34302009-07-29
CVE-2024-38265 6.88.80.01332024-10-08
CVE-2025-55081 6.89.10.00342025-10-15
CVE-2025-36855 6.78.80.00772025-09-08
CVE-2018-8789 6.57.50.05242018-11-29
CVE-2020-3399 6.58.60.01362020-09-24
CVE-2021-1373 6.58.60.01492021-03-24
CVE-2021-1588 6.58.60.01322021-08-25
CVE-2022-20714 6.58.60.01462022-04-15