CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

603 vulnerabilities with CWE-129
CVE-2025-27075 HIGH
Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via Bluetooth Host IOCTL Command
CVSS 7.8
CVE-2025-27067 HIGH
Qualcomm FastConnect and WCD/WSA Firmware - Memory Corruption
CVSS 7.8
CVE-2025-54650 MEDIUM
HarmonyOS - Improper Array Index Validation in Audio Codec Module
CVSS 4.2
CVE-2025-54645 MEDIUM
HarmonyOS - Denial of Service via Location Service Array Index
CVSS 5.0
CVE-2025-54644 MEDIUM
Huawei EMUI and HarmonyOS - Out-of-bounds Read in Kernel Ambient Light Module
CVSS 6.6
CVE-2025-54643 MEDIUM
Huawei EMUI and HarmonyOS - Out-of-bounds Read in Kernel Ambient Light Module
CVSS 6.6
CVE-2025-54610 MEDIUM
HarmonyOS - Denial of Service via Audio Codec Module Out-of-Bounds Access
CVSS 5.4
CVE-2025-23278 HIGH
NVIDIA Display Driver - Buffer Overflow
CVSS 7.1
CVE-2025-38367 HIGH
Linux Kernel 6.13-6.15.5 - Out-of-Bounds Write via LoongArch KVM EIOINTC_ENABLE Register Handling
CVSS 8.8
CVE-2025-38239 HIGH
Linux Kernel 5.17-6.1.142, 6.2-6.6.95, 6.7-6.12.35, 6.13-6.15.4 - Out-of-Bounds Access in megaraid_sas
CVSS 7.3
CVE-2025-38198 HIGH
Linux Kernel - Out-of-Bounds Array Index in fbcon_info_from_console via store_modes sysfs Node
CVSS 7.8
CVE-2025-38146 CRITICAL
Linux kernel - Array Index Out-of-Bounds
CVSS 9.4
CVE-2025-38013 HIGH
Linux kernel - Array Index Out-of-Bounds
CVSS 7.8
CVE-2025-5868 HIGH
RT-Thread 5.1.0 - Improper Restriction of Operations within the Bounds of a Memory Buffer in sys_thread_sigprocmask
CVSS 8.0
CVE-2025-5866 HIGH
RT-Thread 5.1.0 - Improper Restriction of Operations within the Bounds of a Memory Buffer in sys_sigprocmask
CVSS 8.0
CVE-2025-3357 CRITICAL
IBM Tivoli Monitoring <6.3.0.7-SP19 - RCE
CVSS 9.8
CVE-2025-48075 HIGH
Fiber 2.52.6 - Denial of Service via Negative Array Index in BodyParser
CVSS 7.5
CVE-2025-1975 HIGH
Ollama 0.5.11 - Denial of Service via Manifest Spoofing in /api/pull Endpoint
CVSS 7.5
CVE-2025-37752 HIGH
Linux Kernel - Array Index Out-of-Bounds in SFQ Scheduler Configuration
CVSS 7.8
CVE-2025-40114 HIGH
Linux Kernel - Out-of-Bounds Read in veml6075_read_int_time_ms
CVSS 7.8
CVE-2025-40014 HIGH
Linux Kernel 6.14-6.14.2 - Out-of-Bounds Array Access in amd_set_spi_freq
CVSS 7.8
CVE-2025-39728 MEDIUM
Linux Kernel 5.5-6.14.2 - Out-of-Bounds Array Indexing in Samsung Clock Initialization
CVSS 5.5
CVE-2025-22067 HIGH
Linux Kernel 6.12-6.12.22, 6.13-6.13.10, 6.14-6.14.1 - Out-of-Bounds Array Access in cdns_mrvl_xspi_setup_clock
CVSS 7.8
CVE-2025-21447 HIGH
Qualcomm FastConnect 6900/7800, SC8380XP, WCD9380/9385, WSA8840/8845/8845H Firmware Memory Corruption
CVSS 7.8
CVE-2025-21423 HIGH
Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via EnableTestMode Escape Call
CVSS 7.8
Details
Vulnerabilities 603
Exploit Likelihood High