CWE-126
CWE-126 · 4 records · 0 with a public proof-of-concept
Records the NVD classes under CWE-126, highest CVSS first.
- HIGH 7.5CVE-2026-86243
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported ver…
- HIGH 7.4CVE-2026-25288
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
orne firmware · orne · palawan25 firmware · palawan25 · pandeiro firmware · pandeiro
- HIGH 7.1CVE-2026-94286
An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.
- LOW 3.7CVE-2026-97399
The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the…