CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

604 vulnerabilities with CWE-129
CVE-2020-3633 CRITICAL
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapd...
CVSS 9.8
CVE-2020-3630 HIGH
Snapdragon Auto et al - Memory Corruption
CVSS 7.8
CVE-2020-11041 LOW
FreeRDP <= 2.0.0 - Denial of Service via Unchecked Array Index in Sound Backend Configuration
CVSS 2.2
CVE-2020-12022 CRITICAL
Advantech WebAccess < 8.4.4 and 9.0.0 - Remote Code Execution via Array Index Validation Bypass
CVSS 9.8
CVE-2020-8876 MEDIUM
Parallels Desktop 15.1.2-47123 - Info Disclosure
CVSS 5.5
CVE-2020-8875 HIGH
Parallels Desktop 15.1.2-47123 - Privilege Escalation
CVSS 8.8
CVE-2020-5959 MEDIUM
NVIDIA Virtual GPU Manager - Denial of Service via vGPU Plugin Array Index Validation
CVSS 5.5
CVE-2020-5319 HIGH
Dell EMC Unity/Unity XT/UnityVSA < 5.0.2.0.5.009 - Unauthenticated DoS via SSH
CVSS 7.5
CVE-2019-10629 HIGH
Qualcomm Bitra Firmware - Memory Corruption via Crafted Page in API
CVSS 7.8
CVE-2019-10628 HIGH
Qualcomm Snapdragon Firmware - Memory Corruption via TLB Entry Manipulation
CVSS 7.8
CVE-2019-10527 HIGH
Qualcomm APQ8009 Firmware - Memory Corruption via SMEM Partition Manipulation
CVSS 7.8
CVE-2019-14093 HIGH
Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, ...
CVSS 7.8
CVE-2019-14080 CRITICAL
Qualcomm Snapdragon Firmware - Out-of-Bounds Write via SDP SAR Attribute Parsing
CVSS 9.8
CVE-2019-14018 HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Array Access via Carrier Index
CVSS 7.8
CVE-2019-10594 CRITICAL
Qualcomm Snapdragon - Stack Overflow via SDP FMTP Attribute
CVSS 9.8
CVE-2019-14046 HIGH
Snapdragon Auto <QCS605 - Memory Corruption
CVSS 7.8
CVE-2019-14044 HIGH
Qualcomm QCS605/SDM439/SDM630/SDM636/SDM660/SDX24 Firmware - Camera Array Out-of-Bounds Access
CVSS 7.8
CVE-2019-10590 CRITICAL
Qualcomm Snapdragon Firmware - Out-of-Bounds Access via DTS Atom Parsing
CVSS 9.8
CVE-2019-14036 HIGH
Snapdragon Auto et al. - Buffer Overflow
CVSS 7.8
CVE-2019-10611 CRITICAL
Qualcomm Multiple Chips - Buffer Overflow in Clip Processing
CVSS 9.8
CVE-2019-8587 HIGH
Apple Icloud < 7.12 - Out-of-Bounds Write
CVSS 8.8
CVE-2019-10601 HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Access via WMI Message Processing
CVSS 7.8
CVE-2019-10481 HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Access via WMI FW Event Buffer
CVSS 7.8
CVE-2019-2320 CRITICAL
Snapdragon Auto- Snapdragon Compute - Memory Corruption
CVSS 9.8
CVE-2019-10511 CRITICAL
Qualcomm APQ8009 and related firmware - Memory Overflow via GSNDCP Compressed Mode PDU Decoding
CVSS 9.8
Details
Vulnerabilities 604
Exploit Likelihood High