CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

604 vulnerabilities with CWE-129
CVE-2024-38587 MEDIUM
Linux Kernel - Out-of-Bounds Write via Incorrect ARRAY_SIZE() Usage in speakup
CVSS 5.3
CVE-2024-38569 HIGH
Linux Kernel 5.17-6.9.2 - Out-of-Bounds Write in HISI PCIe Event Handling
CVSS 7.8
CVE-2024-38568 HIGH
Linux Kernel 6.0-6.1.92, 6.2-6.6.32, 6.7-6.8.11, 6.9-6.9.2 - Out-of-Bounds Write in HNS3 PMU Event Group Handling
CVSS 7.8
CVE-2024-38562 HIGH
Linux Kernel 6.6-6.6.32, 6.7-6.8.11, 6.9-6.9.2 - Out-of-Bounds Array Indexing in WiFi nl80211 Channel Request Handler
CVSS 7.8
CVE-2024-38556 HIGH
Linux Kernel 5.4.174-5.4.x - Out-of-Bounds Access via mlx5 Core Command Queue Semaphore Timeout
CVSS 7.8
CVE-2024-38552 HIGH
Linux Kernel Out-of-Bounds Write in AMD Display Color Transformation
CVSS 7.8
CVE-2024-38542 HIGH
Linux Kernel 6.8.2-6.8.11, 6.9.0-6.9.2, 6.10 - Improper Array Index Validation in RDMA mana_ib
CVSS 7.1
CVE-2024-36740 HIGH
OneFlow v0.9.1 - Denial of Service via Negative Index Range Exceeding Size
CVSS 7.5
CVE-2024-36743 HIGH
OneFlow v0.9.1 - Denial of Service via Empty Array in oneflow.dot
CVSS 7.5
CVE-2024-36921 HIGH
Linux Kernel - Out-of-Bounds Array Access in iwl_mvm_mld_rm_sta_id
CVSS 7.8
CVE-2024-36015 HIGH
Linux Kernel 4.9.22-4.9.229 - Improper Array Index Validation in ppdev register_device
CVSS 7.8
CVE-2024-22181 HIGH
libigl 2.5.0 - Out-of-Bounds Write via Crafted .node File
CVSS 7.8
CVE-2024-35905 HIGH
Linux Kernel - Use-After-Free in BPF Stack Access Size Validation
CVSS 7.8
CVE-2024-26981 HIGH
Linux Kernel - Out-of-Bounds Read in nilfs_set_de_type
CVSS 7.8
CVE-2024-26971 MEDIUM
Linux Kernel 6.6-6.6.23, 6.7-6.7.11, 6.8-6.8.2 - Out-of-Bounds Read in Clock Frequency Table Traversal
CVSS 5.5
CVE-2024-26969 MEDIUM
Linux Kernel 4.16-6.8.2 - Out-of-Bounds Read via Frequency Table Traversal
CVSS 5.5
CVE-2024-26968 MEDIUM
Linux Kernel 6.4-6.6.23, 6.7.0-6.7.11, 6.8.0-6.8.2 - Out-of-Bounds Access in Clock Frequency Table Traversal
CVSS 5.5
CVE-2024-26967 MEDIUM
Linux Kernel 6.8-6.8.3 - Out-of-Bounds Access in Clock Frequency Table Traversal
CVSS 5.5
CVE-2024-26966 MEDIUM
Linux Kernel 3.17-6.8.2 - Out-of-Bounds Read in Clock Frequency Table
CVSS 5.5
CVE-2024-34050 HIGH
Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 - Memory C...
CVSS 7.5
CVE-2024-34048 CRITICAL
O-RAN RIC I-Release e2mgr - Buffer Overflow
CVSS 9.8
CVE-2024-34047 MEDIUM
O-RAN RIC I-Release - Buffer Overflow
CVSS 4.3
CVE-2024-31581 CRITICAL
FFmpeg n6.1 - Improper Validation of Array Index in libavcodec/cbs_h266_syntax_template.c
CVSS 9.8
CVE-2024-26914 HIGH
Linux Kernel < 6.7.6 - Out-of-Bounds Write in AMD Display MPC Combine Array
CVSS 7.8
CVE-2024-23084 HIGH
Apfloat 1.10.1 - Array Index Out of Bounds Write in DoubleCRTMath
CVSS 7.5
Details
Vulnerabilities 604
Exploit Likelihood High