CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

572 vulnerabilities with CWE-129
CVE-2024-42698 MEDIUM
Roughly Enough Items (REI) <16.0.729 - Improper Validation
CVSS 4.3
CVE-2024-43858 HIGH
Linux Kernel - Array Index Out-of-Bounds in diFree
CVSS 7.8
CVE-2024-43842 HIGH
Linux Kernel 5.16-6.1.103 6.2-6.6.44 6.7-6.10.3 - Out-of-Bounds Read in rtw89_sta_info_get_iter
CVSS 7.8
CVE-2024-42301 HIGH
Linux Kernel < 4.19.320 Buffer Overflow in parport do_hardware_base_addr
CVSS 7.8
CVE-2024-42148 HIGH
Linux Kernel - Array Index Out-of-Bounds in bnx2x Driver
CVSS 7.8
CVE-2024-42121 HIGH
Linux Kernel 4.15-6.9.8 - Out-of-Bounds Write in AMD Display DRM HDCP Handling
CVSS 7.8
CVE-2024-42120 HIGH
Linux Kernel 4.15-6.9.8 - Out-of-Bounds Write in DRM AMD Display
CVSS 7.8
CVE-2024-42117 HIGH
Linux Kernel 6.7-6.9.9 - Out-of-Bounds Array Index Access in DRM AMD Display Plane/Stream ID Lookup
CVSS 7.8
CVE-2024-42092 HIGH
Linux Kernel 4.19-6.9.7 - Out-of-Bounds Array Access in GPIO Davinci IRQ Validation
CVSS 7.8
CVE-2024-42088 HIGH
Linux Kernel 6.8-6.9.7 - Out-of-Bounds Access in mtk_soundcard_common_probe
CVSS 7.8
CVE-2024-41061 HIGH
Linux Kernel 6.7-6.9.11 - Out-of-Bounds Array Index in dml2_calculate_rq_and_dlg_params
CVSS 7.8
CVE-2024-41028 HIGH
Linux Kernel 6.1-6.1.99, 6.2-6.6.40, 6.7-6.9.9 - Array Index Out-of-Bounds Access in toshiba_acpi DMI Quirks
CVSS 7.8
CVE-2024-5680 HIGH
EcoStruxure Foxboro DCS Control Core Services < 9.8 - Local Denial of Service via Foxboro.sys IOCTL Call
CVSS 7.1
CVE-2024-21522 HIGH
audify - Denial of Service via Negative frameSize in OpusDecoder
CVSS 7.5
CVE-2024-32673 MEDIUM
Samsung Open Source Walrus <72c7230f32a0b791355bbdfc78669701024b095...
CVSS 5.5
CVE-2024-39461 MEDIUM
Linux Kernel 6.6-6.6.33, 6.7-6.9.4, 6.10 - Out-of-Bounds Array Access in Raspberry Pi Clock Discovery
CVSS 5.5
CVE-2024-38631 HIGH
Linux Kernel 6.9-6.9.3 - Out-of-Bounds Array Index Access in PAC1934 ADC Driver
CVSS 7.8
CVE-2024-38623 CRITICAL
Linux Kernel 5.15-5.15.160, 5.16-6.1.92, 6.2-6.6.32, 6.7-6.9.3 - Out-of-Bounds Write in NTFS Label Handling
CVSS 9.8
CVE-2024-38587 MEDIUM
Linux Kernel - Out-of-Bounds Write via Incorrect ARRAY_SIZE() Usage in speakup
CVSS 5.3
CVE-2024-38569 HIGH
Linux Kernel 5.17-6.9.2 - Out-of-Bounds Write in HISI PCIe Event Handling
CVSS 7.8
CVE-2024-38568 HIGH
Linux Kernel 6.0-6.1.92, 6.2-6.6.32, 6.7-6.8.11, 6.9-6.9.2 - Out-of-Bounds Write in HNS3 PMU Event Group Handling
CVSS 7.8
CVE-2024-38562 HIGH
Linux Kernel 6.6-6.6.32, 6.7-6.8.11, 6.9-6.9.2 - Out-of-Bounds Array Indexing in WiFi nl80211 Channel Request Handler
CVSS 7.8
CVE-2024-38556 HIGH
Linux Kernel 5.4.174-5.4.x - Out-of-Bounds Access via mlx5 Core Command Queue Semaphore Timeout
CVSS 7.8
CVE-2024-38552 HIGH
Linux Kernel Out-of-Bounds Write in AMD Display Color Transformation
CVSS 7.8
CVE-2024-38542 HIGH
Linux Kernel 6.8.2-6.8.11, 6.9.0-6.9.2, 6.10 - Improper Array Index Validation in RDMA mana_ib
CVSS 7.1
Details
Vulnerabilities 572
Exploit Likelihood High