CWE-1285
Improper Validation of Specified Index, Position, or Offset in Input
The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.
57 vulnerabilities with CWE-1285
CVE-2026-12681
HIGH
Google Go-attestation < 0.6.0 - Improper Validation of Specified Index, Position, or Offset in Input
CVE-2026-8036
HIGH
NI-PAL Through 26.3.0 - Local Privilege Escalation via Memory Access
CVSS 7.1
CVE-2026-45352
MEDIUM
cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding
CVSS 5.3
CVE-2026-9100
MEDIUM
Heap memory out of bounds read and crash in C Driver legacy GridFS file reader
CVSS 5.9
CVE-2026-44004
HIGH
vm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass)
CVSS 7.5
CVE-2026-43868
MEDIUM
Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
CVSS 5.3
CVE-2026-40886
HIGH
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller
CVSS 7.7
CVE-2026-33557
CRITICAL
Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
CVSS 9.1
CVE-2026-32286
HIGH
Denial of service in github.com/jackc/pgproto3/v2
CVSS 7.5
CVE-2026-32285
HIGH
Denial of service in github.com/buger/jsonparser
CVSS 7.5
CVE-2026-20440
MEDIUM
MAE - Privilege Escalation
CVSS 6.7
CVE-2026-2006
HIGH
PostgreSQL 14.0-14.20 - Remote Code Execution via Multibyte Character Length Mismanagement
CVSS 8.8
CVE-2026-20413
MEDIUM
Android MediaTek imgsys - Local Privilege Escalation via Out-of-Bounds Write
CVSS 6.7
CVE-2025-2399
MEDIUM
Mitsubishi Electric CNC M800V/M80V/M800/M80/E80/C80/M700V/M70V/E70 and NC Trainer2 - DoS via TCP Port 683
CVSS 5.9
CVE-2025-20796
HIGH
Android MediaTek imgsys - Local Privilege Escalation via Out-of-Bounds Write
CVSS 7.8
CVE-2025-67268
CRITICAL
gpsd < 3.27.1 - Heap-based Buffer Overflow in NMEA2000 PGN 129540 Packet Handling
CVSS 9.8
CVE-2025-48511
MEDIUM
AMD uProf < 5.0.1174, < 5.0.1223, < 5.0.1479 - Denial of Service via Arbitrary Physical Address Write
CVSS 5.5
CVE-2025-48502
MEDIUM
AMD uProf < 5.0.1174, < 5.0.1223, < 5.0.1479 - Denial of Service via MSR Register Overwrite
CVSS 5.5
CVE-2025-55086
CRITICAL
Eclipse ThreadX NetX Duo < 6.4.4.202503 - Out-of-bounds Read in DHCPV6 Client
CVSS 9.8
CVE-2025-55087
HIGH
NextX Duo <6.4.4 - Memory Corruption
CVSS 7.5
CVE-2025-8291
MEDIUM
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CVE-2025-9189
HIGH
Digilent DASYLab - Out-of-Bounds Write via DSB File Parsing
CVSS 7.8
CVE-2025-57778
HIGH
Digilent DASYLab - Out-of-Bounds Write via DSB File Parsing
CVSS 7.8
CVE-2025-57777
HIGH
Digilent DASYLab - Out-of-Bounds Write in displ2.dll via Crafted DSB File
CVSS 7.8
CVE-2025-57776
HIGH
Digilent DASYLab - Out-of-Bounds Write via DSB File Parsing
CVSS 7.8
Details
Vulnerabilities
57