CWE-1285

Improper Validation of Specified Index, Position, or Offset in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.

46 vulnerabilities with CWE-1285
CVE-2024-10494 HIGH
NI Labview < 2021 - Out-of-Bounds Access
CVSS 7.8
CVE-2024-51566 MEDIUM
NVMe Driver - Use After Free
CVSS 6.5
CVE-2024-51564 HIGH
hda Audio Driver - DoS
CVSS 7.5
CVE-2024-0123 LOW
Nvidia Cuda Toolkit < 12.6.2 - Denial of Service
CVSS 3.3
CVE-2024-41928 HIGH
bhyve - Buffer Overflow
CVSS 8.4
CVE-2024-23612 HIGH
NI Labview < 2020 - Remote Code Execution
CVSS 7.8
CVE-2024-23609 HIGH
NI Labview < 2020 - Remote Code Execution
CVSS 7.8
CVE-2023-46724 HIGH
Squid <6.4 - DoS
CVSS 8.6
CVE-2023-39389 HIGH
PMS - Info Disclosure
CVSS 7.5
CVE-2023-39388 HIGH
PMS - Info Disclosure
CVSS 7.5
CVE-2023-36850 MEDIUM
Juniper Networks Junos OS - DoS
CVSS 6.5
CVE-2023-0859 LOW
Office / Small Office Multifunction Printers and Laser Printers <11...
CVSS 2.2
CVE-2022-22223 MEDIUM
Juniper Networks Junos OS - DoS
CVSS 6.5
CVE-2022-22201 HIGH
Juniper Networks Junos OS - DoS
CVSS 7.5
CVE-2022-36363 MEDIUM
LOGO! <all - RCE
CVSS 5.3
CVE-2022-21821 HIGH
Nvidia Cuda Toolkit < 11.6.2 - Integer Overflow
CVSS 7.8
CVE-2020-25241 HIGH
SIMATIC MV400 - Use After Free
CVSS 7.5
CVE-2019-25625 MEDIUM
Blob Studio 2.17 Denial of Service via Malformed Input
CVSS 6.2
CVE-2019-25622 MEDIUM
Paint Studio 2.17 Denial of Service via Malformed Input
CVSS 6.2
CVE-2019-25593 MEDIUM
jetCast Server 2.0 Denial of Service via Log Directory
CVSS 5.5
CVE-2018-25232 MEDIUM
Softros LAN Messenger 9.2 Denial of Service via Log Files Location
CVSS 5.5
Details
Vulnerabilities 46