CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

572 vulnerabilities with CWE-129
CVE-2023-52728 MEDIUM
onos-lib-go 0.10.25 - Index Out-of-Range Write in putBitString
CVSS 5.5
CVE-2023-52640 HIGH
Linux Kernel < 5.15.150 - Out-of-Bounds Read in ntfs_listxattr
CVSS 7.1
CVE-2023-51455 MEDIUM
DJI drone devices < v1.01.00 - Memory Corruption
CVSS 6.8
CVE-2023-33111 MEDIUM
Qualcomm AR8035 Firmware - Information Disclosure via VI Calibration State Mismatch
CVSS 5.5
CVE-2023-52604 HIGH
Linux Kernel < 4.19.307 - Out-of-Bounds Array Index in JFS dbAdjTree
CVSS 7.8
CVE-2023-52603 HIGH
Linux Kernel < 4.19.307 - Array Index Out-of-Bounds in JFS dtSplitRoot
CVSS 7.8
CVE-2023-52601 HIGH
Linux Kernel < 4.19.307 - Array Index Out-of-Bounds in JFS dbAdjTree
CVSS 7.8
CVE-2023-52599 HIGH
Linux Kernel < 4.19.307 - Array Index Out-of-Bounds in JFS diNewExt
CVSS 7.8
CVE-2023-52594 HIGH
Linux Kernel < 4.19.307 - Array Index Out-of-Bounds Read in ath9k_htc_txstatus
CVSS 7.8
CVE-2023-52451 HIGH
Linux Kernel 4.1.0-4.19.306 - Out-of-Bounds Read in dlpar_memory_remove_by_index
CVSS 7.8
CVE-2023-43535 HIGH
Product <Version - Memory Corruption
CVSS 8.4
CVE-2023-39235 HIGH
GTKWave 3.3.115 - Out-of-Bounds Write in VZT File Autosort Functionality
CVSS 7.8
CVE-2023-39234 HIGH
GTKWave 3.3.115 - Out-of-Bounds Write via VZT File Autosort Functionality
CVSS 7.8
CVE-2023-35997 HIGH
GTKWave 3.3.115 - Remote Code Execution via Crafted .fst File
CVSS 7.8
CVE-2023-35996 HIGH
GTKWave 3.3.115 - Remote Code Execution via Crafted FST File
CVSS 7.8
CVE-2023-35995 HIGH
GTKWave 3.3.115 - Remote Code Execution via Crafted .fst File
CVSS 7.8
CVE-2023-35994 HIGH
GTKWave 3.3.115 - Arbitrary Code Execution via Crafted .fst File
CVSS 7.8
CVE-2023-33053 HIGH
Qualcomm CSR8811 Firmware - Memory Corruption via Metadata Parsing
CVSS 8.4
CVE-2023-6298 MEDIUM
Apryse iText 8.0.2 - Array Index Vulnerability
CVSS 4.3
CVE-2023-46724 HIGH
Squid 3.3.0.1-5.9 and < 6.4 - Denial of Service via Crafted SSL Certificate in TLS Handshake
CVSS 8.6
CVE-2023-35126 HIGH
JustSystems Ichitaro 2023 1.0.1.59372 - Out-of-Bounds Write via DocumentViewStyles and DocumentEditStyles Parsers
CVSS 7.8
CVE-2023-24850 HIGH
Qualcomm KeyMaster Trusted Application Firmware - Memory Corruption
CVSS 7.8
CVE-2023-28573 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 7.8
CVE-2023-28567 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 7.8
CVE-2023-28565 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 7.8
Details
Vulnerabilities 572
Exploit Likelihood High