CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

572 vulnerabilities with CWE-129
CVE-2020-28617 HIGH
CGAL - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28616 HIGH
CGAL 5.1.1 - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28615 HIGH
CGAL 5.1.1 - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28614 HIGH
CGAL 5.1.1 - Out-of-bounds Read and Type Confusion in Nef Polygon Parser
CVSS 8.8
CVE-2020-28613 HIGH
CGAL 5.1.1 - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28612 HIGH
CGAL 5.1.1 - Out-of-bounds Read and Type Confusion in Nef Polygon Parser
CVSS 8.8
CVE-2020-28611 HIGH
CGAL 5.1.1 - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28610 HIGH
CGAL libcgal 5.1.1 - Out-of-bounds Read and Type Confusion in Nef Polygon Parser
CVSS 8.8
CVE-2020-28609 HIGH
CGAL libcgal 5.1.1 - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28608 HIGH
CGAL libcgal 5.1.1 - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28607 HIGH
CGAL - Out-of-bounds Read and Type Confusion in Nef Polygon Parser
CVSS 8.8
CVE-2020-28606 HIGH
CGAL - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28605 HIGH
CGAL 5.1.1 - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28604 HIGH
CGAL - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28603 HIGH
CGAL 5.1.1 - Out-of-bounds Read in Nef Polygon Parser
CVSS 8.8
CVE-2020-28602 HIGH
CGAL 5.1.1 - Out-of-bounds Read and Type Confusion in Nef Polygon Parser
CVSS 8.8
CVE-2020-35635 HIGH
CGAL - Remote Code Execution via Nef Polygon Parsing in SNC_io_parser
CVSS 8.8
CVE-2020-35634 HIGH
CGAL 5.1.1 - Out-of-Bounds Read and Type Confusion via Nef Polygon Parsing
CVSS 8.8
CVE-2020-35633 HIGH
CGAL 5.1.1 - Out-of-Bounds Read and Type Confusion via Nef Polygon Parsing
CVSS 8.8
CVE-2020-28589 HIGH
tinyobjloader v2.0-rc1 and development commit 79d4421 - Remote Code Execution via LoadObj Function
CVSS 8.8
CVE-2020-18430 HIGH
tinyexr 0.9.5 - Denial of Service via Array Index Error in DecodeEXRImage
CVSS 7.5
CVE-2020-18428 HIGH
tinyexr 0.9.5 - Denial of Service via Array Index Error in SaveEXR
CVSS 7.5
CVE-2020-11307 CRITICAL
Qualcomm APQ/MSM/QCA/PM Firmware - Buffer Overflow in Modem Array Index Validation
CVSS 9.8
CVE-2020-11291 CRITICAL
Qualcomm APQ8017 Firmware - Buffer Overflow via IKEv2 Delete Payload Parameter Validation
CVSS 9.8
CVE-2020-11134 CRITICAL
Qualcomm Firmware - Stack-Based Buffer Overflow via NAN Management Frame Attribute Validation
CVSS 9.8
Details
Vulnerabilities 572
Exploit Likelihood High