CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

572 vulnerabilities with CWE-129
CVE-2019-10533 CRITICAL
Qualcomm Snapdragon Firmware - Out-of-Bounds Write via Improper Array Index Validation
CVSS 9.8
CVE-2019-10512 HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Write via Unvalidated Audio Payload Index
CVSS 7.8
CVE-2019-17212 CRITICAL
Arm Mbed OS 5.14.0 - Heap-based and Stack-based Buffer Overflow in CoAP Parser
CVSS 9.8
CVE-2019-10499 HIGH
Qualcomm IPQ4019/IPQ8064/IPQ8074/QCS405/SD 665/SD 675/SD 730/SD 855 Firmware - Out-of-Bounds Access
CVSS 7.8
CVE-2019-14437 HIGH
VLC media player <3.0.7.1 - Buffer Overflow
CVSS 7.8
CVE-2019-15784 CRITICAL
Secure Reliable Transport < 1.3.4 - Array Index Overflow in CSndUList
CVSS 9.8
CVE-2019-13418 HIGH
Search Guard < 24.0 - Improper Validation of Array Index
CVSS 7.5
CVE-2019-2346 HIGH
Qualcomm Snapdragon Firmware - Memory Corruption via Improper Array Index Validation
CVSS 7.8
CVE-2019-2326 HIGH
Qualcomm Snapdragon - Buffer Overflow
CVSS 7.8
CVE-2019-2239 MEDIUM
Qualcomm Snapdragon - Denial of Service
CVSS 5.5
CVE-2019-12957 HIGH
Glyphandcog Xpdfreader - Out-of-Bounds Read
CVSS 7.8
CVE-2019-0906 HIGH
Windows Jet Database Engine - Remote Code Execution via Crafted File
CVSS 7.8
CVE-2019-1837 MEDIUM
Cisco Unified Communications Manager - DoS
CVSS 5.3
CVE-2019-9729 HIGH
Shanda MapleStory Online V160 - Privilege Escalation
CVSS 7.8
CVE-2019-5666 HIGH
NVIDIA Windows GPU Display Driver - DoS or Privilege Escalation via Array Index Validation
CVSS 7.8
CVE-2019-8356 MEDIUM
Sound Exchange - Out-of-Bounds Write
CVSS 5.5
CVE-2019-1000016 MEDIUM
FFmpeg 4.1 - Denial of Service via Crafted AV1 File in libavcodec/cbs_av1.c
CVSS 6.5
CVE-2018-17478 HIGH
Google Chrome < 70.0.3538.102 - Remote Code Execution via V8 Array Index Mismanagement
CVSS 8.8
CVE-2018-5903 HIGH
Snapdragon Auto/Mobile/Industrial/IoT - Out of bounds read
CVSS 7.8
CVE-2018-5883 HIGH
Qualcomm Multiple Chipsets Firmware - Buffer Overflow in WLAN Driver Event Handler
CVSS 7.8
CVE-2018-13902 HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Memory Read via XTRA File Decoding
CVSS 7.5
CVE-2018-11927 HIGH
Snapdragon Auto - Array Index Out of Bounds
CVSS 7.8
CVE-2018-13913 HIGH
Qualcomm Snapdragon Firmware - Unauthorized Access via Improper Array Index Validation in debugFS
CVSS 7.8
CVE-2018-11948 MEDIUM
Snapdragon Auto <various - Info Disclosure
CVSS 5.5
CVE-2018-11899 HIGH
Qualcomm Snapdragon Firmware - Out-of-Bounds Write via Radio Index Validation
CVSS 7.8
Details
Vulnerabilities 572
Exploit Likelihood High