CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

572 vulnerabilities with CWE-129
CVE-2022-49186 HIGH
Linux Kernel 5.17-5.17.1 - Out-of-Bounds Array Access in visconti_clk_register_gates()
CVSS 7.8
CVE-2022-49170 HIGH
Linux kernel - Array Index Out of Bounds
CVSS 7.8
CVE-2022-49022 HIGH
Linux Kernel 5.5-5.10.158, 5.11-5.15.82, 5.16-6.0.12 - Out-of-Bounds Array Access in ieee80211_get_rate_duration
CVSS 7.8
CVE-2022-48979 MEDIUM
Linux Kernel < 6.0.13 - Array Index Out-of-Bounds in DCN32 DML
CVSS 5.5
CVE-2022-48967 HIGH
Linux Kernel Out-of-Bounds Write in NFC NCI Target Array Handling
CVSS 7.1
CVE-2022-48883 HIGH
Linux Kernel 5.17-6.1.6 - Out-of-Bounds Access in PKEY Interface Channel Stats
CVSS 7.8
CVE-2022-48702 HIGH
Linux Kernel < 4.9.328 - Out-of-Bounds Array Access in ALSA emu10k1 Voice Allocator
CVSS 7.8
CVE-2022-40534 HIGH
Qualcomm WCN685X-5 Firmware - Memory Corruption in Audio Array Index Validation
CVSS 8.4
CVE-2022-33275 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 8.4
CVE-2022-48503 HIGH KEV
Safari < 15.6 - Remote Code Execution via Array Index Validation Issue
CVSS 8.8
CVE-2022-33281 MEDIUM
Qualcomm WCN685X-5 Firmware - Memory Corruption via Improper Array Index Validation
CVSS 6.7
CVE-2022-33302 MEDIUM
User Identity Module - Memory Corruption
CVSS 6.8
CVE-2022-33289 MEDIUM
Qualcomm Modem Firmware - Memory Corruption via Malformed APDU
CVSS 6.8
CVE-2022-38072 MEDIUM
ADMesh Master Commit <767a105-0.98.4 - Buffer Overflow
CVSS 6.5
CVE-2022-40539 HIGH
Qualcomm Automotive Android OS - Memory Corruption via Improper Array Index Validation
CVSS 8.4
CVE-2022-40537 HIGH
Qualcomm APQ8009 Firmware - Memory Corruption in Bluetooth HOST via AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP Response
CVSS 7.3
CVE-2022-33256 CRITICAL
Qualcomm Multi-mode Call Processor Firmware - Memory Corruption
CVSS 9.8
CVE-2022-47348 MEDIUM
Android - Local Denial of Service via Missing Permission Check in Engineermode Services
CVSS 5.5
CVE-2022-47347 MEDIUM
Android - Denial of Service in Engineermode Services
CVSS 5.5
CVE-2022-47346 MEDIUM
Android - Local Denial of Service via Missing Permission Check in Engineermode Services
CVSS 5.5
CVE-2022-47345 MEDIUM
Android - Local Denial of Service via Missing Permission Check in Engineermode Services
CVSS 5.5
CVE-2022-47344 MEDIUM
Android - Local Denial of Service via Missing Permission Check in Engineermode Services
CVSS 5.5
CVE-2022-47343 MEDIUM
Android - Local Denial of Service via Missing Permission Check in Engineermode Services
CVSS 5.5
CVE-2022-47342 MEDIUM
Android - Local Denial of Service via Missing Permission Check in Engineermode Services
CVSS 5.5
CVE-2022-33274 HIGH
Qualcomm QAM8295P Firmware - Memory Corruption via Improper Array Index Validation
CVSS 8.4
Details
Vulnerabilities 572
Exploit Likelihood High