CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

604 vulnerabilities with CWE-129
CVE-2018-5838 HIGH
Qualcomm Adreno OpenGL Driver - Out-of-Bounds Access in SurfaceFlinger
CVSS 7.8
CVE-2018-13302 HIGH
FFmpeg - Denial of Service via Crafted AVI to MPEG4 Conversion
CVSS 8.8
CVE-2018-12018 HIGH
Go Ethereum < 1.8.11 - Denial of Service via LES GetBlockHeadersMsg Integer Signedness Error
CVSS 7.5
CVE-2018-5851 HIGH
Android - Buffer Overflow via HTT_T2H_MSG_TYPE_TX_COMPL_IND Message Processing
CVSS 7.8
CVE-2018-3576 HIGH
Android - Array Index Validation Bypass in WiFi Driver sapInterferenceRssiCount()
CVSS 7.8
CVE-2018-11490 HIGH
giflib 3.0.x - Heap-Based Buffer Overflow in DGifDecompressLine
CVSS 8.8
CVE-2018-11489 HIGH
giflib 3.0.x - Heap-Based Buffer Overflow in DGifDecompressLine
CVSS 8.8
CVE-2018-7406 HIGH
Foxit PhantomPDF and Reader < 9.1 - Remote Code Execution via U3D Image Array Indexing
CVSS 8.8
CVE-2018-10120 HIGH
LibreOffice <5.4.6.1-6.0.2.1 - DoS
CVSS 7.8
CVE-2017-18274 HIGH
Qualcomm Mdm9206 Firmware - Improper Array Index Validation
CVSS 7.8
CVE-2017-18309 HIGH
Qualcomm SD 845 and SD 850 Firmware - Arbitrary Memory Read and Write via QMP Transportation Micro-Core
CVSS 7.1
CVE-2017-15857 HIGH
Android - Out-of-Bounds Access in Camera Driver Region Params Copy
CVSS 7.8
CVE-2017-5445 HIGH
Debian Linux < 45.9.0 - Improper Array Index Validation
CVSS 7.5
CVE-2017-15855 HIGH
Qualcomm Android MSM Firefox OS and QRD Android - Kernel Buffer Overflow via Camera CPP Module
CVSS 7.8
CVE-2017-15830 HIGH
Android - Buffer Overflow in sme_set_plm_request
CVSS 7.8
CVE-2017-14889 HIGH
Android - Remote Code Execution via WMI Descriptor Pool Index
CVSS 7.8
CVE-2017-15861 HIGH
Android - Out-of-Bounds Write via Unvalidated vdev_id in wma_roam_synch_event_handler
CVSS 7.8
CVE-2017-16410 HIGH
Adobe Acrobat and Reader <2017.012.20098 - Info Disclosure
CVSS 8.8
CVE-2017-16391 HIGH
Adobe Acrobat and Reader < 11.0.22, 15.0-15.006.30355, 17.0-17.012.20098 - Memory Corruption via Printing Functionality
CVSS 8.8
CVE-2017-8172 MEDIUM
Huawei P10 and P10 Plus Firmware < VKY-AL00C00B157, < VTR-AL00C00B157 - Denial of Service via Isub Service Array Index
CVSS 5.5
CVE-2017-16899 HIGH
Xfig 3.2.6a - Denial of Service or Information Disclosure via Malicious Fig File
CVSS 7.1
CVE-2017-0836 HIGH
Android 5.0.2 5.1.1 6.0 6.0.1 7.0 7.1.1 7.1.2 8.0 - Remote Code Execution in libhevc
CVSS 7.8
CVE-2017-8251 HIGH
Android < 8.0 - Memory Corruption via Unchecked Array Index in Stream Configuration
CVSS 7.8
CVE-2017-0805 HIGH
Android <7.1.2 - Privilege Escalation
CVSS 7.8
CVE-2017-10663 HIGH
Linux Kernel 3.8-3.18.64 - Local Privilege Escalation via Unvalidated F2FS Checkpoint Arrays
CVSS 7.8
Details
Vulnerabilities 604
Exploit Likelihood High