CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

572 vulnerabilities with CWE-129
CVE-2020-3673 CRITICAL
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapd...
CVSS 9.8
CVE-2020-3654 CRITICAL
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapd...
CVSS 9.8
CVE-2020-11174 HIGH
Qualcomm Snapdragon - Array Index Underflow in ADSP Driver
CVSS 7.8
CVE-2020-25796 HIGH
sized-chunks < 0.6.2 - Unaligned Reference Generation in InlineArray Implementation
CVSS 7.5
CVE-2020-25793 HIGH
sized-chunks < 0.6.2 - Improper Validation of Array Index in Chunk Implementation
CVSS 7.5
CVE-2020-25792 HIGH
sized-chunks < 0.6.2 - Improper Validation of Array Index in Chunk pair()
CVSS 7.5
CVE-2020-25791 HIGH
sized-chunks < 0.6.2 - Improper Validation of Array Index in Chunk Implementation
CVSS 7.5
CVE-2020-11881 HIGH
MikroTik RouterOS 6.41.3-6.46.5 & 7.x <7.0 Beta5 - DoS via SMB Packet
CVSS 7.5
CVE-2020-11128 HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Write via Mask File Copy
CVSS 7.8
CVE-2020-17401 MEDIUM
Parallels Desktop 15.1.4 - Info Disclosure
CVSS 6.0
CVE-2020-17400 HIGH
Parallels Desktop 15.1.4 - Privilege Escalation
CVSS 8.8
CVE-2020-17399 HIGH
Parallels Desktop 15.1.4 - Privilege Escalation
CVSS 8.8
CVE-2020-17398 MEDIUM
Parallels Desktop 15.1.4 - Info Disclosure
CVSS 6.5
CVE-2020-17394 MEDIUM
Parallels Desktop 15.1.4 - Info Disclosure
CVSS 6.0
CVE-2020-15112 MEDIUM
etcd <3.3.23, 3.4.10 - Info Disclosure
CVSS 6.5
CVE-2020-3665 HIGH
Snapdragon Auto et al - Buffer Overflow
CVSS 7.8
CVE-2020-3660 CRITICAL
Snapdragon Auto Snapdragon Compute Snapdragon Connectivity Snapdrag...
CVSS 9.8
CVE-2020-10071 CRITICAL
Zephyr < 2.2.0 - Buffer Overflow and Remote Code Execution via MQTT Publish Message Length Field
CVSS 9.0
CVE-2020-3633 CRITICAL
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapd...
CVSS 9.8
CVE-2020-3630 HIGH
Snapdragon Auto et al - Memory Corruption
CVSS 7.8
CVE-2020-11041 LOW
FreeRDP <= 2.0.0 - Denial of Service via Unchecked Array Index in Sound Backend Configuration
CVSS 2.2
CVE-2020-12022 CRITICAL
Advantech WebAccess < 8.4.4 and 9.0.0 - Remote Code Execution via Array Index Validation Bypass
CVSS 9.8
CVE-2020-8876 MEDIUM
Parallels Desktop 15.1.2-47123 - Info Disclosure
CVSS 5.5
CVE-2020-8875 HIGH
Parallels Desktop 15.1.2-47123 - Privilege Escalation
CVSS 8.8
CVE-2020-5959 MEDIUM
NVIDIA Virtual GPU Manager - Denial of Service via vGPU Plugin Array Index Validation
CVSS 5.5
Details
Vulnerabilities 572
Exploit Likelihood High