CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

572 vulnerabilities with CWE-129
CVE-2018-11288 HIGH
Qualcomm Mdm9206 Firmware - Improper Array Index Validation
CVSS 7.8
CVE-2018-4210 HIGH
Safari < 11.1 - Memory Corruption via JavaScript Array Indexing
CVSS 8.8
CVE-2018-17458 HIGH
Google Chrome < 69.0.3497.92 - Remote Code Execution via WebAssembly Dispatch Table
CVSS 8.8
CVE-2018-11996 HIGH
Snapdragon Automobile/Mobile/Wear <various - Buffer Overflow
CVSS 7.8
CVE-2018-5914 HIGH
Snapdragon Mobile/Snapdragon Wear - Info Disclosure
CVSS 7.8
CVE-2018-17848 HIGH
golang/net < 2018-09-25 - Denial of Service via Malformed HTML Parsing
CVSS 7.5
CVE-2018-11269 HIGH
Qualcomm Snapdragon Firmware - Buffer Overflow via TFTP Options Parsing
CVSS 7.8
CVE-2018-11268 HIGH
Qualcomm Snapdragon Firmware - Buffer Overflow via TFTP Options Parsing
CVSS 7.8
CVE-2018-11267 HIGH
Qualcomm Snapdragon Firmware - Memory Corruption via Malformed XML in Firehose
CVSS 7.8
CVE-2018-11903 HIGH
Android - Out-of-Bounds Write in WLAN HOST via WMA Interface Array Index
CVSS 7.8
CVE-2018-11902 HIGH
Android - Out-of-Bounds Access in WLAN HOST via Firmware Value
CVSS 7.8
CVE-2018-11891 HIGH
Android - Out-of-Bounds Read in WLAN HOST Function
CVSS 8.8
CVE-2018-11883 HIGH
Android - Out-of-Bounds Memory Access via WLAN Policy Manager Mode Parameter
CVSS 7.8
CVE-2018-11827 HIGH
Android - Out-of-Bounds Write via WMA Roam Synchronization Handler
CVSS 7.8
CVE-2018-11299 HIGH
Android - Out-of-Bounds Memory Access in WLAN Host Driver via Invalid VDEV ID
CVSS 7.8
CVE-2018-16648 MEDIUM
Artifex MuPDF 1.13.0 - Denial of Service via PDF Device Alpha Array Index Underflow
CVSS 5.5
CVE-2018-11263 HIGH
Android - Out-of-Bounds Write via Radio Stats Buffer Access
CVSS 8.8
CVE-2018-5894 MEDIUM
Qualcomm Multiple Chipsets Firmware - Out-of-bounds Read in MP4 Parser
CVSS 6.5
CVE-2018-5838 HIGH
Qualcomm Adreno OpenGL Driver - Out-of-Bounds Access in SurfaceFlinger
CVSS 7.8
CVE-2018-13302 HIGH
FFmpeg - Denial of Service via Crafted AVI to MPEG4 Conversion
CVSS 8.8
CVE-2018-12018 HIGH
Go Ethereum < 1.8.11 - Denial of Service via LES GetBlockHeadersMsg Integer Signedness Error
CVSS 7.5
CVE-2018-5851 HIGH
Android - Buffer Overflow via HTT_T2H_MSG_TYPE_TX_COMPL_IND Message Processing
CVSS 7.8
CVE-2018-3576 HIGH
Android - Array Index Validation Bypass in WiFi Driver sapInterferenceRssiCount()
CVSS 7.8
CVE-2018-11490 HIGH
giflib 3.0.x - Heap-Based Buffer Overflow in DGifDecompressLine
CVSS 8.8
CVE-2018-11489 HIGH
giflib 3.0.x - Heap-Based Buffer Overflow in DGifDecompressLine
CVSS 8.8
Details
Vulnerabilities 572
Exploit Likelihood High