CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

604 vulnerabilities with CWE-129
CVE-2022-21310 MEDIUM
Oracle MySQL Cluster <= 7.4.34, <= 7.5.24, <= 7.6.20, <= 8.0.27 - Authenticated Remote Code Execution
CVSS 6.3
CVE-2021-4439 HIGH
Linux Kernel < 4.4.290 - Array Index Out-of-Bounds in ISDN CAPI Controller Detachment
CVSS 7.8
CVE-2021-47548 CRITICAL
Linux Kernel < 4.9.292 - Array Index Validation Bypass in hns_dsaf_ge_srst_by_port
CVSS 9.8
CVE-2021-47547 MEDIUM
Linux Kernel < 4.4.294 - Out-of-Bounds Array Access in Tulip DE4X5 PHY ID Handling
CVSS 4.4
CVE-2021-47449 HIGH
Linux Kernel 5.14.4-5.14.14 - Deadlock via Tx Timestamp Tracking Flush
CVSS 7.1
CVE-2021-47135 HIGH
Linux Kernel 5.12-5.12.9 - Array Index Out-of-Bounds Access in mt7921_mcu_tx_rate_report
CVSS 7.8
CVE-2021-47065 HIGH
Linux Kernel rtw88 - Array Index Out-of-Bounds in rtw_get_tx_power_params
CVSS 7.8
CVE-2021-46984 HIGH
Linux Kernel 4.18-5.4.120 - Out-of-Bounds Array Access in Kyber Scheduler
CVSS 7.8
CVE-2021-35126 HIGH
Qualcomm Firmware - Memory Corruption in DSP Service via Improper Input Validation
CVSS 8.4
CVE-2021-35121 MEDIUM
Qualcomm Snapdragon Compute/Connectivity/Industrial IOT/Mobile - Use-After-Free in Synx Driver
CVSS 6.7
CVE-2021-35072 HIGH
Qualcomm APQ8009 and related firmwares - Buffer Overflow via DIAG Command Array Index
CVSS 7.8
CVE-2021-21949 HIGH
Accusoft ImageGear - Out-of-Bounds Write via JPEG-JFIF Scan Header Parser
CVSS 8.8
CVE-2021-21947 HIGH
Accusoft ImageGear 19.10 - Heap-Based Buffer Overflow in JPEG-JFIF Lossless Huffman Parser
CVSS 8.8
CVE-2021-30325 MEDIUM
Qualcomm Firmware - Out-of-Bounds Memory Access in DCI Resource Allocation
CVSS 6.7
CVE-2021-35005 LOW
TeamViewer < 15.18.5.0 - Out-of-bounds Read in TeamViewer Service
CVSS 3.3
CVE-2021-30311 HIGH
Qualcomm AR8035 and Multiple Firmware - Heap Overflow via Improper Array Index Validation
CVSS 7.8
CVE-2021-39985 HIGH
HarmonyOS < 2.0 - Denial of Service in HwNearbyMain Module
CVSS 7.5
CVE-2021-30282 HIGH
Qualcomm AR8031 Firmware - Out-of-Bounds Write in RAM Partition Table
CVSS 8.4
CVE-2021-37062 CRITICAL
HarmonyOS < 2.0 - Memory Overflow and Information Leak via Improper Array Index Validation
CVSS 9.1
CVE-2021-37057 HIGH
HarmonyOS < 2.0 - Denial of Service via Array Index Validation
CVSS 7.5
CVE-2021-30255 HIGH
Qualcomm APQ8009 Firmware - Buffer Overflow via PDM DIAG Command in FTM
CVSS 7.8
CVE-2021-1117 MEDIUM
NVIDIA GPU Display Driver 390-392.68 - Denial of Service via DxgkDdiEscape Handler
CVSS 4.7
CVE-2021-35598 MEDIUM
Oracle MySQL <7.4.33, 7.5.23, 7.6.19, 8.0.26 - Privilege Escalation
CVSS 6.3
CVE-2021-35594 MEDIUM
Oracle MySQL <7.4.33, 7.5.23, 7.6.19, 8.0.26 - Privilege Escalation
CVSS 6.3
CVE-2021-35592 MEDIUM
Oracle MySQL <7.5.23, 7.6.19, 8.0.26 - Privilege Escalation
CVSS 6.3
Details
Vulnerabilities 604
Exploit Likelihood High