CWE-126

CWE-126 · 4 records · 0 with a public proof-of-concept

Records the NVD classes under CWE-126, highest CVSS first.

  1. HIGH 7.5CVE-2026-86243

    Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported ver…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.4CVE-2026-25288

    Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

    orne firmware · orne · palawan25 firmware · palawan25 · pandeiro firmware · pandeiro

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.1CVE-2026-94286

    An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.

    AI risk analysis on Exploit-DB.ai →

  4. LOW 3.7CVE-2026-97399

    The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the…

    AI risk analysis on Exploit-DB.ai →