CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

572 vulnerabilities with CWE-129
CVE-2025-71100 HIGH
Linux Kernel - Out-of-Bounds Array Index in rtl92cu_tx_fill_desc()
CVSS 7.8
CVE-2025-71086 HIGH
Linux Kernel Invalid Array Index in rose_kill_by_device()
CVSS 7.8
CVE-2025-47393 HIGH
Qualcomm Firmware - Memory Corruption via Improper Array Index Validation
CVSS 7.8
CVE-2025-15271 HIGH
FontForge - Remote Code Execution via SFD File Parsing
CVSS 8.8
CVE-2025-15270 HIGH
FontForge - Remote Code Execution via SFD File Parsing Array Index Validation
CVSS 8.8
CVE-2025-65562 HIGH
free5gc - Unauthenticated Denial of Service via PFCP Session Deletion Request SEID Underflow
CVSS 7.5
CVE-2025-66559 HIGH
Taiko Alethia <2.3.1 - Info Disclosure
CVE-2025-61915 MEDIUM
OpenPrinting CUPS <2.4.15 - Memory Corruption
CVSS 6.0
CVE-2025-0657 HIGH
Automated Logic and Carrier i-Vu Gen5 router drv_gen5_106-01-2380 -...
CVE-2025-65499 MEDIUM
libcoap 4.3.5 - Denial of Service via Crafted DTLS Handshake
CVSS 4.3
CVE-2025-62372 MEDIUM
vLLM 0.5.5-0.11.1 - Denial of Service via Multimodal Embedding Input Shape Mismatch
CVSS 6.5
CVE-2025-10158 MEDIUM
Rsync - Out-of-Bounds Read via Negative Array Index
CVSS 4.3
CVE-2025-47361 HIGH
Qualcomm Firmware - Memory Corruption via Out-of-Range Identifier
CVSS 7.8
CVE-2025-47352 HIGH
Qualcomm FastConnect 7800 Firmware - Memory Corruption during Audio Streaming
CVSS 7.8
CVE-2025-27034 CRITICAL
Qualcomm Modem and FastConnect Firmware - Memory Corruption in PLMN Selection
CVSS 9.8
CVE-2025-23338 LOW
NVIDIA CUDA Toolkit < 13.0.0 - Denial of Service via Malicious ELF File in nvdisasm
CVSS 3.3
CVE-2025-39823 HIGH
Linux Kernel 4.19-6.16.5 - KVM x86 Guest-Controlled Indices Array Index Validation Issue
CVSS 7.8
CVE-2025-38697 HIGH
Linux Kernel JFS Out-of-Bounds Write in dbAllocAG Tree Index
CVSS 7.8
CVE-2025-57052 CRITICAL
davegamble/cjson 1.5.0-1.7.18 - Out-of-bounds Read via Malformed JSON Pointer Strings
CVSS 9.8
CVE-2025-27075 HIGH
Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via Bluetooth Host IOCTL Command
CVSS 7.8
CVE-2025-27067 HIGH
Qualcomm FastConnect and WCD/WSA Firmware - Memory Corruption
CVSS 7.8
CVE-2025-54650 MEDIUM
HarmonyOS - Improper Array Index Validation in Audio Codec Module
CVSS 4.2
CVE-2025-54645 MEDIUM
HarmonyOS - Denial of Service via Location Service Array Index
CVSS 5.0
CVE-2025-54644 MEDIUM
Huawei EMUI and HarmonyOS - Out-of-bounds Read in Kernel Ambient Light Module
CVSS 6.6
CVE-2025-54643 MEDIUM
Huawei EMUI and HarmonyOS - Out-of-bounds Read in Kernel Ambient Light Module
CVSS 6.6
Details
Vulnerabilities 572
Exploit Likelihood High