CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

604 vulnerabilities with CWE-129
CVE-2024-26758 MEDIUM
Linux Kernel 3.0-6.7.6 - Denial of Service via Suspended Array Handling in md_check_recovery()
CVSS 5.5
CVE-2024-26755 MEDIUM
Linux Kernel 6.7-6.7.6 - Deadlock via Interrupted Reshape and Spare Disk Addition
CVSS 5.3
CVE-2024-26699 HIGH
Linux Kernel < 6.7.6 - Array Index Out-of-Bounds in dcn35_clkmgr
CVSS 7.8
CVE-2024-29231 MEDIUM
Synology Surveillance Station < 9.2.0-9289 - Authenticated Info Disclosure & DoS via UserPrivilege.Enum
CVSS 5.4
CVE-2024-2214 HIGH
Eclipse ThreadX <6.4.0 - Memory Corruption
CVSS 7.0
CVE-2024-0901 HIGH
WolfSSL 3.12.2 through 5.6.6 - Memory Corruption
CVSS 7.5
CVE-2024-21493 MEDIUM
caddy-security - Denial of Service via Caddyfile Array Index Parsing
CVSS 5.3
CVE-2024-24563 CRITICAL
vyperlang/vyper < 0.3.10 and pypi/vyper < 0.4.0 - Improper Array Index Validation
CVSS 9.8
CVE-2023-31309 MEDIUM
Amd Radeon™ RX 6000 Series Graphics Products - Improper Validation of Array Index
CVE-2023-20601 MEDIUM
AMD Radeon PRO VII - Denial of Service via RAS TA Driver Input Validation
CVE-2023-53485 HIGH
Linux Kernel 2.6.12.1-4.14.323 - Array Index Out-of-Bounds in JFS dbAllocDmapLev
CVSS 7.8
CVE-2023-53395 HIGH
Linux Kernel < 4.14.326 - Array Index Out-of-Bounds in ACPI Interpreter
CVSS 7.8
CVE-2023-53340 HIGH
Linux Kernel 5.18-6.1.30, 6.3.0-6.3.4, 6.4+ - Array Index Out-of-Bounds in mlx5 DEVX Command Handling
CVSS 7.8
CVE-2023-53192 HIGH
Linux Kernel 5.8-5.10.190 - Out-of-Bounds Access in VXLAN Nexthop Hash Handling
CVSS 7.8
CVE-2023-31306 LOW
AMD Graphics Driver - Info Disclosure
CVSS 3.3
CVE-2023-53019 HIGH
Linux Kernel 4.5-4.14.305 - Out-of-Bounds Access in MDIO Bus PHY Address Handling
CVSS 7.8
CVE-2023-53000 HIGH
Linux Kernel 2.6.15-5.4.230 - Spectre v1 Gadget via Netlink Attribute Type Index
CVSS 7.8
CVE-2023-52988 HIGH
Linux Kernel 3.1-4.14.305 - Out-of-Bounds Array Access in ALSA HDA Via add_secret_dac_path()
CVSS 7.8
CVE-2023-52987 HIGH
Linux Kernel 6.1-6.1.10 - Array Index Underflow in ASoC SOF IPC4 Priority Mask DFS Write
CVSS 7.8
CVE-2023-31307 LOW
Power Management Firmware - Memory Corruption
CVSS 2.3
CVE-2023-52835 HIGH
Linux Kernel < 4.19.300 - Denial of Service via Large AUX Area Allocation
CVSS 7.8
CVE-2023-52819 MEDIUM
Linux Kernel < 4.14.331 - Out-of-Bounds Array Index in DRM AMD Polaris and Tonga PPTABLE
CVSS 6.6
CVE-2023-52818 HIGH
Linux Kernel < 4.14.331 - Out-of-Bounds Array Index in AMD DRM SMU7 PPTable Handling
CVSS 7.8
CVE-2023-52812 HIGH
Linux kernel - Array Index Out-of-Bounds in DRM AMD PCIe Parameter Update
CVSS 7.8
CVE-2023-52807 HIGH
Linux Kernel - Out-of-Bounds Read in HNS3 DebugFS Coalesce Info
CVSS 7.8
Details
Vulnerabilities 604
Exploit Likelihood High