CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

603 vulnerabilities with CWE-129
CVE-2025-21991 HIGH
Linux Kernel - Out-of-Bounds Memory Access in AMD Microcode Loading
CVSS 7.8
CVE-2025-30077 MEDIUM
onos-lib-go 0.10.28 - Denial of Service via Zero numBits in ASN.1 Aper GetBitString
CVSS 6.2
CVE-2025-21692 HIGH
Linux kernel - Privilege Escalation
CVSS 7.8
CVE-2025-21680 HIGH
Linux Kernel 5.15-6.12.10 - Out-of-Bounds Array Access in pktgen get_imix_entries
CVSS 7.8
CVE-2024-21970 MEDIUM
AMD Ryzen Threadripper 3000/5000 and Athlon 3000 Series Processors - Memory Corruption via AGESA Array Index Validation
CVSS 4.4
CVE-2024-53009 MEDIUM
Qualcomm AQT1000 Firmware - Memory Corruption via Mailbox Operation
CVSS 5.3
CVE-2024-35164 MEDIUM
Apache Guacamole < 1.6.0 - Remote Code Execution via Terminal Emulator Console Code Injection
CVSS 6.8
CVE-2024-45578 HIGH
Qualcomm FastConnect 6900 Firmware - Memory Corruption via IFE Output Resource ID Validation
CVSS 7.8
CVE-2024-45576 HIGH
Qualcomm FastConnect 6900 Firmware - Memory Corruption in OPE Module via Command Buffer Processing
CVSS 7.8
CVE-2024-45574 HIGH
Qualcomm SDM429W Firmware - Memory Corruption in Camera Kernel via Invalid Array Index
CVSS 7.8
CVE-2024-53014 HIGH
Qualcomm FastConnect 7800 Firmware - Memory Corruption in Audio Driver Port and Channel Validation
CVSS 7.8
CVE-2024-49836 HIGH
Qualcomm Camera Frame Processing Pipeline Firmware - Memory Corruption
CVSS 7.8
CVE-2024-57996 MEDIUM
Linux Kernel - Array Index Out-of-Bounds in SFQ Scheduler via Packet Limit Handling
CVSS 5.5
CVE-2024-49843 HIGH
Qualcomm FastConnect and QCA/QCM/QCS Firmware - Memory Corruption in GPU AHB Bus Error Handling
CVSS 7.8
CVE-2024-49837 HIGH
VMware <version> - Memory Corruption
CVSS 7.8
CVE-2024-49834 HIGH
Camera Sensor <Version - Memory Corruption
CVSS 7.8
CVE-2024-49833 HIGH
Qualcomm FastConnect and QAM Firmware - Memory Corruption in Camera
CVSS 7.8
CVE-2024-49832 HIGH
Qualcomm FastConnect and Multiple Firmware - Memory Corruption in Camera
CVSS 7.8
CVE-2024-45582 HIGH
Qualcomm FastConnect 6900 Firmware - Memory Corruption in Camera Kernel Device Validation
CVSS 7.8
CVE-2024-45569 CRITICAL
Qualcomm AR8035 Firmware - Memory Corruption via ML IE Frame Parsing
CVSS 9.8
CVE-2024-45550 HIGH
Qualcomm Fastconnect 6900 Firmware - Improper Array Index Validation
CVSS 7.8
CVE-2024-56616 HIGH
Linux Kernel Memory Corruption via MST Sideband Message Body Length Check
CVSS 7.8
CVE-2024-56608 HIGH
Linux Kernel - Out-of-Bounds Array Access in dcn21_link_encoder_create
CVSS 7.8
CVE-2024-56598 HIGH
Linux Kernel - Out-of-Bounds Array Index Access in JFS dtReadFirst
CVSS 7.8
CVE-2024-56596 HIGH
Linux Kernel - Array Index Out-of-Bounds in jfs_readdir
CVSS 7.8
Details
Vulnerabilities 603
Exploit Likelihood High