CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

604 vulnerabilities with CWE-129
CVE-2023-6298 MEDIUM
Apryse iText 8.0.2 - Array Index Vulnerability
CVSS 4.3
CVE-2023-46724 HIGH
Squid 3.3.0.1-5.9 and < 6.4 - Denial of Service via Crafted SSL Certificate in TLS Handshake
CVSS 8.6
CVE-2023-35126 HIGH
JustSystems Ichitaro 2023 1.0.1.59372 - Out-of-Bounds Write via DocumentViewStyles and DocumentEditStyles Parsers
CVSS 7.8
CVE-2023-24850 HIGH
Qualcomm KeyMaster Trusted Application Firmware - Memory Corruption
CVSS 7.8
CVE-2023-28573 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 7.8
CVE-2023-28567 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 7.8
CVE-2023-28565 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 7.8
CVE-2023-28558 HIGH
WLAN <Tx Status Handler - Memory Corruption
CVSS 7.8
CVE-2023-28557 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 7.8
CVE-2023-28548 HIGH
Qualcomm WLAN HAL - Memory Corruption
CVSS 7.8
CVE-2023-21636 MEDIUM
Qualcomm AQT1000 Firmware - Memory Corruption via Improper Array Index Validation
CVSS 6.7
CVE-2023-36307 MEDIUM
ZPLGFA 1.1.1 - Denial of Service via Zero-Width Image Processing
CVSS 5.5
CVE-2023-36308 MEDIUM
Disintegration Imaging 1.6.2 - Info Disclosure
CVSS 5.5
CVE-2023-21650 MEDIUM
GPS HLOS Driver - Memory Corruption
CVSS 6.7
CVE-2023-29458 MEDIUM
Zabbix - Denial of Service via Duktape Valstack Overflow
CVSS 5.9
CVE-2023-31194 MEDIUM
Diagon v1.0.139 - Memory Corruption
CVSS 5.3
CVE-2023-2570 HIGH
Schneider Electric EcoStruxure Foxboro DCS Control Core Services - Local DoS and Kernel Execution via IOCTL
CVSS 7.0
CVE-2023-0950 HIGH
LibreOffice 7.4.0-7.4.5 and 7.5.0 - Remote Code Execution via Malformed Spreadsheet Formula
CVSS 7.8
CVE-2023-28004 CRITICAL
PowerLogic HDPM6000 Firmware < 0.58.6 - Denial of Service or Remote Code Execution via Ethernet Request
CVSS 9.8
CVE-2023-2008 HIGH
Linux Kernel < 5.19 - Privilege Escalation via udmabuf Fault Handler Array Index Validation
CVSS 7.8
CVE-2023-26066 CRITICAL
Lexmark <2023-02-19 - Info Disclosure
CVSS 9.8
CVE-2023-20080 HIGH
Cisco IOS - Unauthenticated Denial of Service via DHCPv6 Message Handling
CVSS 8.6
CVE-2023-20633 MEDIUM
Android - Local Privilege Escalation via USB Missing Bounds Check
CVSS 6.7
CVE-2023-0755 CRITICAL
GE Digital Industrial Gateway Server < 7.612 - Remote Code Execution via Array Index Validation
CVSS 9.8
CVE-2023-22408 HIGH
Juniper Junos OS on SRX 5000 Series DoS via Malformed SIP SDP Field
CVSS 7.5
Details
Vulnerabilities 604
Exploit Likelihood High