CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

604 vulnerabilities with CWE-129
CVE-2017-0737 HIGH
Android 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2 - Elevation of Privilege in Media Framework
CVSS 7.8
CVE-2017-0716 HIGH
Android 6.0 6.0.1 7.0 7.1.1 7.1.2 - Remote Code Execution in libmpeg2
CVSS 7.8
CVE-2017-8797 HIGH
Linux Kernel < 4.11.3 - Denial of Service via NFSv4 pNFS GETDEVICEINFO or LAYOUTGET Operand
CVSS 7.5
CVE-2017-0347 HIGH
NVIDIA Windows GPU Display Driver - Denial of Service or Privilege Escalation via DxgkDdiEscape Array Index
CVSS 7.8
CVE-2017-0345 HIGH
NVIDIA Windows GPU Display Driver - Denial of Service or Privilege Escalation via DxgDdiEscape Array Index Validation
CVSS 7.8
CVE-2017-7228 HIGH
Xen 4.4.x-4.8.x - Improper Validation of Array Index in XENMEM_exchange
CVSS 8.2
CVE-2017-0322 HIGH
NVIDIA Windows GPU Display Driver - Denial of Service or Privilege Escalation via Array Index Validation
CVSS 7.8
CVE-2016-10454 CRITICAL
Qualcomm SD 425, SD 430, SD 450, and SD 625 Firmware - Out-of-Bounds Array Index in QTEE API
CVSS 9.8
CVE-2016-10386 CRITICAL
Google Android - Improper Array Index Validation
CVSS 9.8
CVE-2016-9053 CRITICAL
Aerospike Database Server <3.10.0.3 - RCE
CVSS 9.8
CVE-2016-8816 HIGH
NVIDIA Windows GPU Display Driver - Privilege Escalation
CVSS 7.8
CVE-2016-8815 HIGH
NVIDIA Windows GPU Display Driver - Privilege Escalation
CVSS 7.8
CVE-2016-7170 MEDIUM
QEMU < 2.7.1 - Denial of Service via vmsvga_fifo_run DEFINE_CURSOR Command
CVSS 4.4
CVE-2015-8366 CRITICAL
LibRaw < 0.17.1 - Memory Corruption via smal_decode_segment Array Index Error
CVSS 9.8
CVE-2015-8316 MEDIUM
LightDM 1.14.3 and 1.16.x < 1.16.6 - Denial of Service via XDMCP Request Packet
CVSS 5.9
CVE-2014-9990 CRITICAL
Qualcomm Snapdragon Mobile and Wear Firmware - Out-of-Bounds Array Access via Improper Index Validation
CVSS 9.8
CVE-2014-9989 CRITICAL
Qualcomm Snapdragon Mobile and Wear Firmware - Out-of-Bounds Array Access in USB Management Module
CVSS 9.8
CVE-2014-10048 CRITICAL
Qualcomm Snapdragon Mobile and Wear Firmware - Array Index Out-of-Bounds Write in Time-Services Offset Handling
CVSS 9.8
CVE-2014-10044 HIGH
Qualcomm Mdm9615 Firmware - Improper Array Index Validation
CVSS 7.5
CVE-2014-4616 MEDIUM
Python 2.7.0-2.7.6 and simplejson < 2.6.1 - Memory Read via Negative Array Index in _json raw_decode
CVSS 5.9
CVE-2014-9948 HIGH
Android TrustZone - Improper Validation of Array Index
CVSS 7.8
CVE-2014-6317
Windows Kernel-Mode Drivers - Denial of Service via Crafted TrueType Font
CVE-2013-1593 HIGH
SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, 7.30 SP04 - Denial of Service via WRITE_C Function in msg_server.exe
CVSS 7.5
CVE-2011-1169
Linux Kernel < 2.6.38.1 - Memory Corruption or Privilege Escalation via AudioScience HPI Driver Adapter Index
CVE-2010-2806
FreeType < 2.4.2 - Heap-Based Buffer Overflow via Negative Size Values in FontType42 Font Files
Details
Vulnerabilities 604
Exploit Likelihood High