CWE-129
High likelihoodImproper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
572 vulnerabilities with CWE-129
CVE-2024-36740
HIGH
OneFlow v0.9.1 - Denial of Service via Negative Index Range Exceeding Size
CVSS 7.5
CVE-2024-36743
HIGH
OneFlow v0.9.1 - Denial of Service via Empty Array in oneflow.dot
CVSS 7.5
CVE-2024-36921
HIGH
Linux Kernel - Out-of-Bounds Array Access in iwl_mvm_mld_rm_sta_id
CVSS 7.8
CVE-2024-36015
HIGH
Linux Kernel 4.9.22-4.9.229 - Improper Array Index Validation in ppdev register_device
CVSS 7.8
CVE-2024-22181
HIGH
libigl 2.5.0 - Out-of-Bounds Write via Crafted .node File
CVSS 7.8
CVE-2024-35905
HIGH
Linux Kernel - Use-After-Free in BPF Stack Access Size Validation
CVSS 7.8
CVE-2024-26981
HIGH
Linux Kernel - Out-of-Bounds Read in nilfs_set_de_type
CVSS 7.8
CVE-2024-26971
MEDIUM
Linux Kernel 6.6-6.6.23, 6.7-6.7.11, 6.8-6.8.2 - Out-of-Bounds Read in Clock Frequency Table Traversal
CVSS 5.5
CVE-2024-26969
MEDIUM
Linux Kernel 4.16-6.8.2 - Out-of-Bounds Read via Frequency Table Traversal
CVSS 5.5
CVE-2024-26968
MEDIUM
Linux Kernel 6.4-6.6.23, 6.7.0-6.7.11, 6.8.0-6.8.2 - Out-of-Bounds Access in Clock Frequency Table Traversal
CVSS 5.5
CVE-2024-26967
MEDIUM
Linux Kernel 6.8-6.8.3 - Out-of-Bounds Access in Clock Frequency Table Traversal
CVSS 5.5
CVE-2024-26966
MEDIUM
Linux Kernel 3.17-6.8.2 - Out-of-Bounds Read in Clock Frequency Table
CVSS 5.5
CVE-2024-34050
HIGH
Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 - Memory C...
CVSS 7.5
CVE-2024-34048
CRITICAL
O-RAN RIC I-Release e2mgr - Buffer Overflow
CVSS 9.8
CVE-2024-34047
MEDIUM
O-RAN RIC I-Release - Buffer Overflow
CVSS 4.3
CVE-2024-31581
CRITICAL
FFmpeg n6.1 - Improper Validation of Array Index in libavcodec/cbs_h266_syntax_template.c
CVSS 9.8
CVE-2024-26914
HIGH
Linux Kernel < 6.7.6 - Out-of-Bounds Write in AMD Display MPC Combine Array
CVSS 7.8
CVE-2024-23084
HIGH
Apfloat 1.10.1 - Array Index Out of Bounds Write in DoubleCRTMath
CVSS 7.5
CVE-2024-26758
MEDIUM
Linux Kernel 3.0-6.7.6 - Denial of Service via Suspended Array Handling in md_check_recovery()
CVSS 5.5
CVE-2024-26755
MEDIUM
Linux Kernel 6.7-6.7.6 - Deadlock via Interrupted Reshape and Spare Disk Addition
CVSS 5.3
CVE-2024-26699
HIGH
Linux Kernel < 6.7.6 - Array Index Out-of-Bounds in dcn35_clkmgr
CVSS 7.8
CVE-2024-29231
MEDIUM
Synology Surveillance Station < 9.2.0-9289 - Authenticated Info Disclosure & DoS via UserPrivilege.Enum
CVSS 5.4
CVE-2024-2214
HIGH
Eclipse ThreadX <6.4.0 - Memory Corruption
CVSS 7.0
CVE-2024-0901
HIGH
WolfSSL 3.12.2 through 5.6.6 - Memory Corruption
CVSS 7.5
CVE-2024-21493
MEDIUM
caddy-security - Denial of Service via Caddyfile Array Index Parsing
CVSS 5.3
Details
Vulnerabilities
572
Exploit Likelihood
High