CWE-1285

Improper Validation of Specified Index, Position, or Offset in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.

57 vulnerabilities with CWE-1285
CVE-2022-36363 MEDIUM
Siemens LOGO! 8 BM Firmware - Information Disclosure via Improper Offset Validation in TCP Packets
CVSS 5.3
CVE-2022-21821 HIGH
NVIDIA CUDA Toolkit < 11.6.2 - Integer Overflow in cuobjdump
CVSS 7.8
CVE-2020-25241 HIGH
SIMATIC MV400 Family < 7.0.6 - TCP Session Termination via Invalid RST Sequence Number
CVSS 7.5
CVE-2019-25625 MEDIUM
Blob Studio 2.17 Denial of Service via Malformed Input
CVSS 6.2
CVE-2019-25622 MEDIUM
Paint Studio 2.17 Denial of Service via Malformed Input
CVSS 6.2
CVE-2019-25593 MEDIUM
jetCast Server 2.0 Denial of Service via Log Directory
CVSS 5.5
CVE-2018-25232 MEDIUM
Softros LAN Messenger 9.2 Denial of Service via Log Files Location
CVSS 5.5
Details
Vulnerabilities 57