CWE-129
High likelihoodImproper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
572 vulnerabilities with CWE-129
CVE-2020-11294
MEDIUM
Qualcomm AR8035 Firmware - Out-of-Bounds Write in Logger via Prefix Size
CVSS 5.9
CVE-2020-11308
MEDIUM
Qualcomm Firmware - Buffer Overflow via ASCII to Unicode String Conversion
CVSS 6.8
CVE-2020-11227
CRITICAL
Qualcomm APQ8009 Firmware - Out-of-Bounds Write via RTT/TTY Packet Parsing
CVSS 9.8
CVE-2020-11226
HIGH
Qualcomm APQ8009 Firmware - Out-of-bounds Read in Data Modem
CVSS 7.5
CVE-2020-25241
HIGH
SIMATIC MV400 Family < 7.0.6 - TCP Session Termination via Invalid RST Sequence Number
CVSS 7.5
CVE-2020-35636
CRITICAL
CGAL - Out-of-bounds Read in Nef Polygon Parser
CVSS 9.8
CVE-2020-35628
CRITICAL
CGAL - Out-of-bounds Read in Nef Polygon Parser
CVSS 9.8
CVE-2020-28636
CRITICAL
CGAL - Out-of-bounds Read in Nef Polygon Parser
CVSS 9.8
CVE-2020-28601
CRITICAL
CGAL - Out-of-bounds Read in Nef Polygon Parser
CVSS 9.8
CVE-2020-11271
HIGH
Qualcomm AQT1000 Firmware - Out-of-Bounds Write via Race Condition in Global Control Elements
CVSS 7.8
CVE-2020-11187
HIGH
Qualcomm Firmware - Memory Corruption in BSI Module via Improper Parameter Count Validation
CVSS 7.8
CVE-2020-11163
CRITICAL
Qualcomm Firmware - Buffer Overflow via IKEv2 Parameter Update
CVSS 9.8
CVE-2020-11146
HIGH
Qualcomm Snapdragon - Out-of-Bounds Write via IOCTL Array Index
CVSS 7.8
CVE-2020-36067
HIGH
gjson <= 1.6.5 - Denial of Service via Crafted GET Call
CVSS 7.5
CVE-2020-28852
HIGH
golang/text < 0.3.5 - Denial of Service via BCP 47 Tag Parsing
CVSS 7.5
CVE-2020-28851
HIGH
GO - Improper Array Index Validation
CVSS 7.5
CVE-2020-29245
MEDIUM
dhowden <2020-11-19 - Info Disclosure
CVSS 6.5
CVE-2020-29244
MEDIUM
dhowden <2020-11-19 - Info Disclosure
CVSS 6.5
CVE-2020-29243
MEDIUM
dhowden <2020-11-19 - Use After Free
CVSS 6.5
CVE-2020-29242
MEDIUM
dhowden <2020-11-19 - Use After Free
CVSS 6.5
CVE-2020-20412
MEDIUM
StepMania 5.0.12 - Denial of Service via Crafted OGG File
CVSS 6.5
CVE-2020-27485
CRITICAL
Garmin Forerunner 235 <8.20 - Memory Corruption
CVSS 9.9
CVE-2020-27483
CRITICAL
Garmin Forerunner 235 <8.20 - Memory Corruption
CVSS 9.9
CVE-2020-3639
CRITICAL
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapd...
CVSS 9.8
CVE-2020-3632
HIGH
Snapdragon Compute/Snapdragon Mobile - Memory Overflow
CVSS 7.8
Details
Vulnerabilities
572
Exploit Likelihood
High