CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

604 vulnerabilities with CWE-129
CVE-2023-52805 HIGH
Linux Kernel < 4.14.331 - Array Index Out-of-Bounds in JFS diAlloc
CVSS 7.8
CVE-2023-52804 HIGH
Linux Kernel < 4.14.331 - Array Index Out-of-Bounds in JFS db_agfree
CVSS 7.8
CVE-2023-52799 HIGH
Linux Kernel < 4.14.331 - Array Index Out-of-Bounds in JFS dbFindLeaf
CVSS 7.8
CVE-2023-52768 MEDIUM
Linux Kernel 5.15.68-5.15.139 - Out-of-Bounds Write in WiFi wilc1000 vmm_table
CVSS 5.6
CVE-2023-40477 HIGH
WinRAR < 6.23 - Remote Code Execution via Recovery Volume Processing
CVSS 7.8
CVE-2023-27349 HIGH
BlueZ - Remote Code Execution via AVRCP Protocol Array Index Validation
CVSS 8.0
CVE-2023-52649 HIGH
Linux Kernel - Out-of-Bounds Read in DRM VKMS LUT Array Indexing
CVSS 7.8
CVE-2023-52728 MEDIUM
onos-lib-go 0.10.25 - Index Out-of-Range Write in putBitString
CVSS 5.5
CVE-2023-52640 HIGH
Linux Kernel < 5.15.150 - Out-of-Bounds Read in ntfs_listxattr
CVSS 7.1
CVE-2023-51455 MEDIUM
DJI drone devices < v1.01.00 - Memory Corruption
CVSS 6.8
CVE-2023-33111 MEDIUM
Qualcomm AR8035 Firmware - Information Disclosure via VI Calibration State Mismatch
CVSS 5.5
CVE-2023-52604 HIGH
Linux Kernel < 4.19.307 - Out-of-Bounds Array Index in JFS dbAdjTree
CVSS 7.8
CVE-2023-52603 HIGH
Linux Kernel < 4.19.307 - Array Index Out-of-Bounds in JFS dtSplitRoot
CVSS 7.8
CVE-2023-52601 HIGH
Linux Kernel < 4.19.307 - Array Index Out-of-Bounds in JFS dbAdjTree
CVSS 7.8
CVE-2023-52599 HIGH
Linux Kernel < 4.19.307 - Array Index Out-of-Bounds in JFS diNewExt
CVSS 7.8
CVE-2023-52594 HIGH
Linux Kernel < 4.19.307 - Array Index Out-of-Bounds Read in ath9k_htc_txstatus
CVSS 7.8
CVE-2023-52451 HIGH
Linux Kernel 4.1.0-4.19.306 - Out-of-Bounds Read in dlpar_memory_remove_by_index
CVSS 7.8
CVE-2023-43535 HIGH
Product <Version - Memory Corruption
CVSS 8.4
CVE-2023-39235 HIGH
GTKWave 3.3.115 - Out-of-Bounds Write in VZT File Autosort Functionality
CVSS 7.8
CVE-2023-39234 HIGH
GTKWave 3.3.115 - Out-of-Bounds Write via VZT File Autosort Functionality
CVSS 7.8
CVE-2023-35997 HIGH
GTKWave 3.3.115 - Remote Code Execution via Crafted .fst File
CVSS 7.8
CVE-2023-35996 HIGH
GTKWave 3.3.115 - Remote Code Execution via Crafted FST File
CVSS 7.8
CVE-2023-35995 HIGH
GTKWave 3.3.115 - Remote Code Execution via Crafted .fst File
CVSS 7.8
CVE-2023-35994 HIGH
GTKWave 3.3.115 - Arbitrary Code Execution via Crafted .fst File
CVSS 7.8
CVE-2023-33053 HIGH
Qualcomm CSR8811 Firmware - Memory Corruption via Metadata Parsing
CVSS 8.4
Details
Vulnerabilities 604
Exploit Likelihood High