CWE-129
High likelihoodImproper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
572 vulnerabilities with CWE-129
CVE-2016-10454
CRITICAL
Qualcomm SD 425, SD 430, SD 450, and SD 625 Firmware - Out-of-Bounds Array Index in QTEE API
CVSS 9.8
CVE-2016-10386
CRITICAL
Google Android - Improper Array Index Validation
CVSS 9.8
CVE-2016-9053
CRITICAL
Aerospike Database Server <3.10.0.3 - RCE
CVSS 9.8
CVE-2016-8816
HIGH
NVIDIA Windows GPU Display Driver - Privilege Escalation
CVSS 7.8
CVE-2016-8815
HIGH
NVIDIA Windows GPU Display Driver - Privilege Escalation
CVSS 7.8
CVE-2016-7170
MEDIUM
QEMU < 2.7.1 - Denial of Service via vmsvga_fifo_run DEFINE_CURSOR Command
CVSS 4.4
CVE-2015-8366
CRITICAL
LibRaw < 0.17.1 - Memory Corruption via smal_decode_segment Array Index Error
CVSS 9.8
CVE-2015-8316
MEDIUM
LightDM 1.14.3 and 1.16.x < 1.16.6 - Denial of Service via XDMCP Request Packet
CVSS 5.9
CVE-2014-9990
CRITICAL
Qualcomm Snapdragon Mobile and Wear Firmware - Out-of-Bounds Array Access via Improper Index Validation
CVSS 9.8
CVE-2014-9989
CRITICAL
Qualcomm Snapdragon Mobile and Wear Firmware - Out-of-Bounds Array Access in USB Management Module
CVSS 9.8
CVE-2014-10048
CRITICAL
Qualcomm Snapdragon Mobile and Wear Firmware - Array Index Out-of-Bounds Write in Time-Services Offset Handling
CVSS 9.8
CVE-2014-10044
HIGH
Qualcomm Mdm9615 Firmware - Improper Array Index Validation
CVSS 7.5
CVE-2014-4616
MEDIUM
Python 2.7.0-2.7.6 and simplejson < 2.6.1 - Memory Read via Negative Array Index in _json raw_decode
CVSS 5.9
CVE-2014-9948
HIGH
Android TrustZone - Improper Validation of Array Index
CVSS 7.8
CVE-2014-6317
Windows Kernel-Mode Drivers - Denial of Service via Crafted TrueType Font
CVE-2013-1593
HIGH
SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, 7.30 SP04 - Denial of Service via WRITE_C Function in msg_server.exe
CVSS 7.5
CVE-2011-1169
Linux Kernel < 2.6.38.1 - Memory Corruption or Privilege Escalation via AudioScience HPI Driver Adapter Index
CVE-2010-2806
FreeType < 2.4.2 - Heap-Based Buffer Overflow via Negative Size Values in FontType42 Font Files
CVE-2009-3080
Linux Kernel < 2.6.32-rc8 - Local Privilege Escalation via Negative Event Index in gdth_read_event
CVE-2007-5756
WinPcap < 4.0.2 - Local Privilege Escalation via Crafted IOCTL Requests
CVE-2005-0369
MEDIUM
Armagetron < 0.2.6.0 and Armagetron Advanced < 0.2.7.0 - Denial of Service via Large Descriptor ID or Claim ID
CVSS 5.3
CVE-2003-0721
Pine < 4.58 - Remote Code Execution via Negative Array Index in rfc2231_get_param
Details
Vulnerabilities
572
Exploit Likelihood
High