CWE-129
High likelihoodImproper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
572 vulnerabilities with CWE-129
CVE-2019-10533
CRITICAL
Qualcomm Snapdragon Firmware - Out-of-Bounds Write via Improper Array Index Validation
CVSS 9.8
CVE-2019-10512
HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Write via Unvalidated Audio Payload Index
CVSS 7.8
CVE-2019-17212
CRITICAL
Arm Mbed OS 5.14.0 - Heap-based and Stack-based Buffer Overflow in CoAP Parser
CVSS 9.8
CVE-2019-10499
HIGH
Qualcomm IPQ4019/IPQ8064/IPQ8074/QCS405/SD 665/SD 675/SD 730/SD 855 Firmware - Out-of-Bounds Access
CVSS 7.8
CVE-2019-14437
HIGH
VLC media player <3.0.7.1 - Buffer Overflow
CVSS 7.8
CVE-2019-15784
CRITICAL
Secure Reliable Transport < 1.3.4 - Array Index Overflow in CSndUList
CVSS 9.8
CVE-2019-13418
HIGH
Search Guard < 24.0 - Improper Validation of Array Index
CVSS 7.5
CVE-2019-2346
HIGH
Qualcomm Snapdragon Firmware - Memory Corruption via Improper Array Index Validation
CVSS 7.8
CVE-2019-2326
HIGH
Qualcomm Snapdragon - Buffer Overflow
CVSS 7.8
CVE-2019-2239
MEDIUM
Qualcomm Snapdragon - Denial of Service
CVSS 5.5
CVE-2019-12957
HIGH
Glyphandcog Xpdfreader - Out-of-Bounds Read
CVSS 7.8
CVE-2019-0906
HIGH
Windows Jet Database Engine - Remote Code Execution via Crafted File
CVSS 7.8
CVE-2019-1837
MEDIUM
Cisco Unified Communications Manager - DoS
CVSS 5.3
CVE-2019-9729
HIGH
Shanda MapleStory Online V160 - Privilege Escalation
CVSS 7.8
CVE-2019-5666
HIGH
NVIDIA Windows GPU Display Driver - DoS or Privilege Escalation via Array Index Validation
CVSS 7.8
CVE-2019-8356
MEDIUM
Sound Exchange - Out-of-Bounds Write
CVSS 5.5
CVE-2019-1000016
MEDIUM
FFmpeg 4.1 - Denial of Service via Crafted AV1 File in libavcodec/cbs_av1.c
CVSS 6.5
CVE-2018-17478
HIGH
Google Chrome < 70.0.3538.102 - Remote Code Execution via V8 Array Index Mismanagement
CVSS 8.8
CVE-2018-5903
HIGH
Snapdragon Auto/Mobile/Industrial/IoT - Out of bounds read
CVSS 7.8
CVE-2018-5883
HIGH
Qualcomm Multiple Chipsets Firmware - Buffer Overflow in WLAN Driver Event Handler
CVSS 7.8
CVE-2018-13902
HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Memory Read via XTRA File Decoding
CVSS 7.5
CVE-2018-11927
HIGH
Snapdragon Auto - Array Index Out of Bounds
CVSS 7.8
CVE-2018-13913
HIGH
Qualcomm Snapdragon Firmware - Unauthorized Access via Improper Array Index Validation in debugFS
CVSS 7.8
CVE-2018-11948
MEDIUM
Snapdragon Auto <various - Info Disclosure
CVSS 5.5
CVE-2018-11899
HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Write via Radio Index Validation
CVSS 7.8
Details
Vulnerabilities
572
Exploit Likelihood
High