CWE-129 · 610 записей
Improper Validation of Array Index
CVE этого класса
612 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
66На этой неделе | CVE-2022-48503Готовый эксплойт | The issue was addressed with improved bounds checks.apple · safari · CWE-129 | Высокая8,8 | KEV | 3,2 % | 14 авг. 2023 г. |
43В плане | CVE-2023-0755Эксплойта нет | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotege · digital industrial gateway server · CWE-129 | Критическая9,8 | — | 11,8 % | 23 февр. 2023 г. |
41В плане | CVE-2021-35592Эксплойта нет | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).oracle · mysql cluster · CWE-129 | Средняя6,3 | — | 52,5 % | 20 окт. 2021 г. |
41В плане | CVE-2016-9053Эксплойта нет | An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3.aerospike · database server · CWE-129 | Критическая9,8 | — | 7,2 % | 21 февр. 2017 г. |
41В плане | CVE-2015-8366Эксплойта нет | Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and posslibraw · libraw · CWE-129 | Критическая9,8 | — | 5,1 % | 14 янв. 2020 г. |
40В плане | CVE-2021-35598Эксплойта нет | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).oracle · mysql cluster · CWE-129 | Средняя6,3 | — | 51,1 % | 20 окт. 2021 г. |
40В плане | CVE-2021-35594Эксплойта нет | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).oracle · mysql cluster · CWE-129 | Средняя6,3 | — | 51,1 % | 20 окт. 2021 г. |
40В плане | CVE-2020-35636Эксплойта нет | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_pcgal · computational geometry algorithms library · CWE-129 | Критическая9,8 | — | 3,3 % | 4 мар. 2021 г. |
40В плане | CVE-2019-17212Эксплойта нет | Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0.mbed · mbed · CWE-129 | Критическая9,8 | — | 3,1 % | 5 нояб. 2019 г. |
40В плане | CVE-2020-28601Эксплойта нет | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.cgal · computational geometry algorithms library · CWE-129 | Критическая9,8 | — | 2,9 % | 4 мар. 2021 г. |
40В плане | CVE-2020-35628Эксплойта нет | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.cgal · computational geometry algorithms library · CWE-129 | Критическая9,8 | — | 2,9 % | 4 мар. 2021 г. |
40В плане | CVE-2020-28636Эксплойта нет | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.cgal · computational geometry algorithms library · CWE-129 | Критическая9,8 | — | 2,9 % | 4 мар. 2021 г. |
40В плане | CVE-2020-27483Эксплойта нет | Garmin Forerunner 235 before 8.20 is affected by: Array index error.garmin · forerunner 235 firmware · CWE-129 | Критическая9,9 | — | 2,1 % | 16 нояб. 2020 г. |
40В плане | CVE-2019-15784Эксплойта нет | Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.srtalliance · secure reliable transport · CWE-129 | Критическая9,8 | — | 2,0 % | 29 авг. 2019 г. |
40В плане | CVE-2020-27485Эксплойта нет | Garmin Forerunner 235 before 8.20 is affected by: Array index error.garmin · forerunner 235 firmware · CWE-129 | Критическая9,9 | — | 1,7 % | 16 нояб. 2020 г. |
40В плане | CVE-2020-12022Эксплойта нет | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.advantech · webaccess · CWE-129 | Критическая9,8 | — | 1,7 % | 8 мая 2020 г. |
39Наблюдать | CVE-2024-24563Эксплойта нет | Vyper array negative index vulnerabilityvyperlang · vyper · CWE-129 | Критическая9,8 | — | 1,5 % | 7 февр. 2024 г. |
39Наблюдать | CVE-2021-47548Эксплойта нет | ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()linux · linux kernel · CWE-129 | Критическая9,8 | — | 1,4 % | 24 мая 2024 г. |
39Наблюдать | CVE-2014-10048Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSqualcomm · mdm9206 firmware · CWE-129 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2016-10454Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE APIqualcomm · sd 425 firmware · CWE-129 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2014-9989Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDqualcomm · mdm9206 firmware · CWE-129 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2014-9990Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDqualcomm · mdm9206 firmware · CWE-129 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2022-26100Эксплойта нет | SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive.sap · sapcar · CWE-129 | Критическая9,8 | — | 1,2 % | 10 мар. 2022 г. |
39Наблюдать | CVE-2023-28004Эксплойта нет | A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial oschneider-electric · powerlogic hdpm6000 firmware · CWE-129 | Критическая9,8 | — | 1,1 % | 18 апр. 2023 г. |
39Наблюдать | CVE-2024-31581Эксплойта нет | FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c.ffmpeg · ffmpeg · CWE-129 | Критическая9,8 | — | 1,1 % | 17 апр. 2024 г. |
- CVE-2022-4850366На этой неделе
The issue was addressed with improved bounds checks.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 3 %apple · safari14 авг. 2023 г.
- CVE-2023-075543В плане
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remote
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %ge · digital industrial gateway server23 февр. 2023 г.
- CVE-2021-3559241В плане
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).
СредняяCVSS 6,3Эксплойта нетEPSS 52 %oracle · mysql cluster20 окт. 2021 г.
- CVE-2016-905341В плане
An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %aerospike · database server21 февр. 2017 г.
- CVE-2015-836641В плане
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and poss
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %libraw · libraw14 янв. 2020 г.
- CVE-2021-3559840В плане
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).
СредняяCVSS 6,3Эксплойта нетEPSS 51 %oracle · mysql cluster20 окт. 2021 г.
- CVE-2021-3559440В плане
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).
СредняяCVSS 6,3Эксплойта нетEPSS 51 %oracle · mysql cluster20 окт. 2021 г.
- CVE-2020-3563640В плане
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_p
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cgal · computational geometry algorithms library4 мар. 2021 г.
- CVE-2019-1721240В плане
Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mbed · mbed5 нояб. 2019 г.
- CVE-2020-2860140В плане
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cgal · computational geometry algorithms library4 мар. 2021 г.
- CVE-2020-3562840В плане
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cgal · computational geometry algorithms library4 мар. 2021 г.
- CVE-2020-2863640В плане
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cgal · computational geometry algorithms library4 мар. 2021 г.
- CVE-2020-2748340В плане
Garmin Forerunner 235 before 8.20 is affected by: Array index error.
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %garmin · forerunner 235 firmware16 нояб. 2020 г.
- CVE-2019-1578440В плане
Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %srtalliance · secure reliable transport29 авг. 2019 г.
- CVE-2020-2748540В плане
Garmin Forerunner 235 before 8.20 is affected by: Array index error.
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %garmin · forerunner 235 firmware16 нояб. 2020 г.
- CVE-2020-1202240В плане
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %advantech · webaccess8 мая 2020 г.
- CVE-2024-2456339Наблюдать
Vyper array negative index vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %vyperlang · vyper7 февр. 2024 г.
- CVE-2021-4754839Наблюдать
ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %linux · linux kernel24 мая 2024 г.
- CVE-2014-1004839Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MS
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9206 firmware18 апр. 2018 г.
- CVE-2016-1045439Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE API
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · sd 425 firmware18 апр. 2018 г.
- CVE-2014-998939Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9206 firmware18 апр. 2018 г.
- CVE-2014-999039Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9206 firmware18 апр. 2018 г.
- CVE-2022-2610039Наблюдать
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sap · sapcar10 мар. 2022 г.
- CVE-2023-2800439Наблюдать
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial o
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %schneider-electric · powerlogic hdpm6000 firmware18 апр. 2023 г.
- CVE-2024-3158139Наблюдать
FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ffmpeg · ffmpeg17 апр. 2024 г.