CWE-129
High likelihoodImproper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
604 vulnerabilities with CWE-129
CVE-2017-0737
HIGH
Android 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2 - Elevation of Privilege in Media Framework
CVSS 7.8
CVE-2017-0716
HIGH
Android 6.0 6.0.1 7.0 7.1.1 7.1.2 - Remote Code Execution in libmpeg2
CVSS 7.8
CVE-2017-8797
HIGH
Linux Kernel < 4.11.3 - Denial of Service via NFSv4 pNFS GETDEVICEINFO or LAYOUTGET Operand
CVSS 7.5
CVE-2017-0347
HIGH
NVIDIA Windows GPU Display Driver - Denial of Service or Privilege Escalation via DxgkDdiEscape Array Index
CVSS 7.8
CVE-2017-0345
HIGH
NVIDIA Windows GPU Display Driver - Denial of Service or Privilege Escalation via DxgDdiEscape Array Index Validation
CVSS 7.8
CVE-2017-7228
HIGH
Xen 4.4.x-4.8.x - Improper Validation of Array Index in XENMEM_exchange
CVSS 8.2
CVE-2017-0322
HIGH
NVIDIA Windows GPU Display Driver - Denial of Service or Privilege Escalation via Array Index Validation
CVSS 7.8
CVE-2016-10454
CRITICAL
Qualcomm SD 425, SD 430, SD 450, and SD 625 Firmware - Out-of-Bounds Array Index in QTEE API
CVSS 9.8
CVE-2016-10386
CRITICAL
Google Android - Improper Array Index Validation
CVSS 9.8
CVE-2016-9053
CRITICAL
Aerospike Database Server <3.10.0.3 - RCE
CVSS 9.8
CVE-2016-8816
HIGH
NVIDIA Windows GPU Display Driver - Privilege Escalation
CVSS 7.8
CVE-2016-8815
HIGH
NVIDIA Windows GPU Display Driver - Privilege Escalation
CVSS 7.8
CVE-2016-7170
MEDIUM
QEMU < 2.7.1 - Denial of Service via vmsvga_fifo_run DEFINE_CURSOR Command
CVSS 4.4
CVE-2015-8366
CRITICAL
LibRaw < 0.17.1 - Memory Corruption via smal_decode_segment Array Index Error
CVSS 9.8
CVE-2015-8316
MEDIUM
LightDM 1.14.3 and 1.16.x < 1.16.6 - Denial of Service via XDMCP Request Packet
CVSS 5.9
CVE-2014-9990
CRITICAL
Qualcomm Snapdragon Mobile and Wear Firmware - Out-of-Bounds Array Access via Improper Index Validation
CVSS 9.8
CVE-2014-9989
CRITICAL
Qualcomm Snapdragon Mobile and Wear Firmware - Out-of-Bounds Array Access in USB Management Module
CVSS 9.8
CVE-2014-10048
CRITICAL
Qualcomm Snapdragon Mobile and Wear Firmware - Array Index Out-of-Bounds Write in Time-Services Offset Handling
CVSS 9.8
CVE-2014-10044
HIGH
Qualcomm Mdm9615 Firmware - Improper Array Index Validation
CVSS 7.5
CVE-2014-4616
MEDIUM
Python 2.7.0-2.7.6 and simplejson < 2.6.1 - Memory Read via Negative Array Index in _json raw_decode
CVSS 5.9
CVE-2014-9948
HIGH
Android TrustZone - Improper Validation of Array Index
CVSS 7.8
CVE-2014-6317
Windows Kernel-Mode Drivers - Denial of Service via Crafted TrueType Font
CVE-2013-1593
HIGH
SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, 7.30 SP04 - Denial of Service via WRITE_C Function in msg_server.exe
CVSS 7.5
CVE-2011-1169
Linux Kernel < 2.6.38.1 - Memory Corruption or Privilege Escalation via AudioScience HPI Driver Adapter Index
CVE-2010-2806
FreeType < 2.4.2 - Heap-Based Buffer Overflow via Negative Size Values in FontType42 Font Files
Details
Vulnerabilities
604
Exploit Likelihood
High