CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

572 vulnerabilities with CWE-129
CVE-2024-47249 MEDIUM
Apache NimBLE <1.8.0 - Memory Corruption
CVSS 5.0
CVE-2024-50291 MEDIUM
Linux Kernel 6.8-6.11.8 - Out-of-Bounds Write via dvb_vb2_expbuf Buffer Index
CVSS 5.5
CVE-2024-50161 MEDIUM
Linux Kernel 6.11-6.11.5 - Out-of-Bounds Array Index in BPF BTF Field Parsing
CVSS 5.5
CVE-2024-51517 MEDIUM
Phone Service Module - Memory Corruption
CVSS 5.1
CVE-2024-33032 MEDIUM
Qualcomm WSA8835 and other Firmware - Memory Corruption via Asynchronous Shared Memory Access
CVSS 6.7
CVE-2024-50007 HIGH
Linux Kernel - Out-of-Bounds Array Access in ASIHPI Driver
CVSS 7.8
CVE-2024-49970 MEDIUM
Linux Kernel < 6.11.3 - Buffer Overflow in DCN401 Stream Encoder Creation
CVSS 5.5
CVE-2024-49969 HIGH
Linux Kernel - Out-of-Bounds Write in DCN30 Color Transformation via cm3_helper_translate_curve_to_hw_format
CVSS 7.8
CVE-2024-49931 HIGH
Linux Kernel - Out-of-Bounds Array Access in ath12k WiFi SoC Stats
CVSS 7.8
CVE-2024-49930 HIGH
Linux Kernel - Out-of-Bounds Array Access in ath11k WiFi SoC Stats
CVSS 7.8
CVE-2024-49895 HIGH
Linux Kernel - Out-of-Bounds Write in DCN30 Degamma Hardware Format Translation
CVSS 7.8
CVE-2024-49894 HIGH
Linux Kernel Out-of-Bounds Write in Degamma Hardware Format Translation
CVSS 7.8
CVE-2024-46871 HIGH
Linux Kernel - Out-of-Bounds Array Access in AMDGPU DMUB Notification Handler
CVSS 7.8
CVE-2024-46859 HIGH
Linux Kernel - Out-of-Bounds Array Access in Panasonic Laptop SINF Handling
CVSS 7.8
CVE-2024-46847 MEDIUM
Linux Kernel 6.6.37-6.6.51 - Out-of-Bounds Access in vmap_block Initialization
CVSS 5.5
CVE-2024-46836 HIGH
Linux Kernel - Out-of-Bounds Array Access in Aspeed UDC Endpoint Index Validation
CVSS 7.8
CVE-2024-46833 HIGH
Linux Kernel < 6.10 - Array Index Validation Bypass in HNS3 SSU Register Query
CVSS 7.8
CVE-2024-46821 HIGH
Linux Kernel - Out-of-Bounds Read in DRM AMD Power Management
CVSS 7.8
CVE-2024-46818 HIGH
Linux Kernel - Out-of-Bounds Write via Invalid GPIO ID Array Index
CVSS 7.8
CVE-2024-46814 HIGH
Linux Kernel - Out-of-Bounds Write in DRM AMD Display HDCP Message Handling
CVSS 7.8
CVE-2024-46813 HIGH
Linux Kernel - Out-of-Bounds Read in DRM AMD Display Link Index Validation
CVSS 7.8
CVE-2024-46811 HIGH
Linux Kernel - Out-of-Bounds Array Index Access in drm/amd/display fpu_update_bw_bounding_box
CVSS 7.8
CVE-2024-46804 HIGH
Linux Kernel - Out-of-Bounds Write in AMD Display HDCP DDC Access
CVSS 7.8
CVE-2024-41565 MEDIUM
JustEnoughItems < 11.6.0.1021 - Item Duplication via Unvalidated Slot Index
CVSS 4.3
CVE-2024-41564 MEDIUM
EMI < 1.1.10 - Improper Validation of Array Index in Slot Handling
CVSS 4.3
Details
Vulnerabilities 572
Exploit Likelihood High