CWE-129
High likelihoodImproper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
572 vulnerabilities with CWE-129
CVE-2026-45624
MEDIUM
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
CVSS 5.1
CVE-2026-45359
MEDIUM
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
CVSS 5.7
CVE-2026-24181
HIGH
Nvidia Dali - Improper Validation of Array Index
CVSS 7.3
CVE-2026-25276
HIGH
Qualcomm Snapdragon Secure Processor - Strongbox Bounds Check Memory Corruption
CVSS 8.8
CVE-2026-46163
HIGH
wifi: b43legacy: enforce bounds check on firmware key index in RX path
CVSS 7.8
CVE-2026-45104
HIGH
MapServer: NULL pointer dereference in SLD `<ElseFilter>` rule parsing reachable via WMS `SLD_BODY`
CVSS 7.5
CVE-2026-46598
MEDIUM
Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
CVSS 5.3
CVE-2026-44310
MEDIUM
gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
CVSS 5.4
CVE-2026-44222
MEDIUM
vLLM: Remote DoS via Special-Token Placeholders
CVSS 6.5
CVE-2026-41643
HIGH
GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
CVSS 7.5
CVE-2026-40251
MEDIUM
Incus out-of-bounds panic in snapshot metadata handling allows denial of service
CVSS 6.5
CVE-2026-31776
HIGH
ALSA: ctxfi: Fix missing SPDIFI1 index handling
CVSS 7.8
CVE-2026-31764
HIGH
iio: imu: st_lsm6dsx: Set buffer sampling frequency for accelerometer only
CVSS 7.8
CVE-2026-31729
HIGH
usb: typec: ucsi: validate connector number in ucsi_notify_common()
CVSS 7.8
CVE-2026-40886
HIGH
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller
CVSS 7.7
CVE-2026-6840
MEDIUM
Samsung ONE <1.30.0 - Memory Corruption
CVSS 5.5
CVE-2026-40097
LOW
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
CVSS 3.7
CVE-2026-34942
MEDIUM
Wasmtime panics when transcoding misaligned utf-16 strings
CVSS 6.5
CVE-2026-21413
CRITICAL
LibRaw - Heap-Based Buffer Overflow in lossless_jpeg_load_raw
CVSS 9.8
CVE-2026-23448
HIGH
net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check
CVSS 7.8
CVE-2026-23447
HIGH
net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
CVSS 7.8
CVE-2026-33762
LOW
go-git: Missing validation decoding Index v4 files leads to panic
CVSS 2.8
CVE-2026-32286
HIGH
Denial of service in github.com/jackc/pgproto3/v2
CVSS 7.5
CVE-2026-32285
HIGH
Denial of service in github.com/buger/jsonparser
CVSS 7.5
CVE-2026-23354
HIGH
x86/fred: Correct speculative safety in fred_extint()
CVSS 7.8
Details
Vulnerabilities
572
Exploit Likelihood
High