CWE-129 · 610 records
Improper Validation of Array Index
CVEs in this class
615 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
66This week | CVE-2022-48503Weaponized | The issue was addressed with improved bounds checks.apple · safari · CWE-129 | High8.8 | KEV | 3.2% | Aug 14, 2023 |
43Plan | CVE-2023-0755No exploit | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotege · digital industrial gateway server · CWE-129 | Critical9.8 | — | 11.8% | Feb 23, 2023 |
41Plan | CVE-2021-35592No exploit | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).oracle · mysql cluster · CWE-129 | Medium6.3 | — | 52.5% | Oct 20, 2021 |
41Plan | CVE-2016-9053No exploit | An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3.aerospike · database server · CWE-129 | Critical9.8 | — | 7.2% | Feb 21, 2017 |
41Plan | CVE-2015-8366No exploit | Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and posslibraw · libraw · CWE-129 | Critical9.8 | — | 5.1% | Jan 14, 2020 |
40Plan | CVE-2021-35598No exploit | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).oracle · mysql cluster · CWE-129 | Medium6.3 | — | 51.1% | Oct 20, 2021 |
40Plan | CVE-2021-35594No exploit | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).oracle · mysql cluster · CWE-129 | Medium6.3 | — | 51.1% | Oct 20, 2021 |
40Plan | CVE-2020-35636No exploit | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_pcgal · computational geometry algorithms library · CWE-129 | Critical9.8 | — | 3.3% | Mar 4, 2021 |
40Plan | CVE-2019-17212No exploit | Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0.mbed · mbed · CWE-129 | Critical9.8 | — | 3.1% | Nov 5, 2019 |
40Plan | CVE-2020-28601No exploit | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.cgal · computational geometry algorithms library · CWE-129 | Critical9.8 | — | 2.9% | Mar 4, 2021 |
40Plan | CVE-2020-35628No exploit | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.cgal · computational geometry algorithms library · CWE-129 | Critical9.8 | — | 2.9% | Mar 4, 2021 |
40Plan | CVE-2020-28636No exploit | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.cgal · computational geometry algorithms library · CWE-129 | Critical9.8 | — | 2.9% | Mar 4, 2021 |
40Plan | CVE-2020-27483No exploit | Garmin Forerunner 235 before 8.20 is affected by: Array index error.garmin · forerunner 235 firmware · CWE-129 | Critical9.9 | — | 2.1% | Nov 16, 2020 |
40Plan | CVE-2019-15784No exploit | Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.srtalliance · secure reliable transport · CWE-129 | Critical9.8 | — | 2.0% | Aug 29, 2019 |
40Plan | CVE-2020-27485No exploit | Garmin Forerunner 235 before 8.20 is affected by: Array index error.garmin · forerunner 235 firmware · CWE-129 | Critical9.9 | — | 1.7% | Nov 16, 2020 |
40Plan | CVE-2020-12022No exploit | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.advantech · webaccess · CWE-129 | Critical9.8 | — | 1.7% | May 8, 2020 |
39Monitor | CVE-2024-24563No exploit | Vyper array negative index vulnerabilityvyperlang · vyper · CWE-129 | Critical9.8 | — | 1.5% | Feb 7, 2024 |
39Monitor | CVE-2021-47548No exploit | ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()linux · linux kernel · CWE-129 | Critical9.8 | — | 1.4% | May 24, 2024 |
39Monitor | CVE-2014-10048No exploit | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSqualcomm · mdm9206 firmware · CWE-129 | Critical9.8 | — | 1.2% | Apr 18, 2018 |
39Monitor | CVE-2016-10454No exploit | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE APIqualcomm · sd 425 firmware · CWE-129 | Critical9.8 | — | 1.2% | Apr 18, 2018 |
39Monitor | CVE-2014-9989No exploit | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDqualcomm · mdm9206 firmware · CWE-129 | Critical9.8 | — | 1.2% | Apr 18, 2018 |
39Monitor | CVE-2014-9990No exploit | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDqualcomm · mdm9206 firmware · CWE-129 | Critical9.8 | — | 1.2% | Apr 18, 2018 |
39Monitor | CVE-2022-26100No exploit | SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive.sap · sapcar · CWE-129 | Critical9.8 | — | 1.2% | Mar 10, 2022 |
39Monitor | CVE-2023-28004No exploit | A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial oschneider-electric · powerlogic hdpm6000 firmware · CWE-129 | Critical9.8 | — | 1.1% | Apr 18, 2023 |
39Monitor | CVE-2024-31581No exploit | FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c.ffmpeg · ffmpeg · CWE-129 | Critical9.8 | — | 1.1% | Apr 17, 2024 |
- CVE-2022-4850366This week
The issue was addressed with improved bounds checks.
HighCVSS 8.8KEVWeaponizedEPSS 3%apple · safariAug 14, 2023
- CVE-2023-075543Plan
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remote
CriticalCVSS 9.8No exploitEPSS 12%ge · digital industrial gateway serverFeb 23, 2023
- CVE-2021-3559241Plan
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).
MediumCVSS 6.3No exploitEPSS 52%oracle · mysql clusterOct 20, 2021
- CVE-2016-905341Plan
An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3.
CriticalCVSS 9.8No exploitEPSS 7%aerospike · database serverFeb 21, 2017
- CVE-2015-836641Plan
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and poss
CriticalCVSS 9.8No exploitEPSS 5%libraw · librawJan 14, 2020
- CVE-2021-3559840Plan
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).
MediumCVSS 6.3No exploitEPSS 51%oracle · mysql clusterOct 20, 2021
- CVE-2021-3559440Plan
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).
MediumCVSS 6.3No exploitEPSS 51%oracle · mysql clusterOct 20, 2021
- CVE-2020-3563640Plan
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_p
CriticalCVSS 9.8No exploitEPSS 3%cgal · computational geometry algorithms libraryMar 4, 2021
- CVE-2019-1721240Plan
Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0.
CriticalCVSS 9.8No exploitEPSS 3%mbed · mbedNov 5, 2019
- CVE-2020-2860140Plan
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
CriticalCVSS 9.8No exploitEPSS 3%cgal · computational geometry algorithms libraryMar 4, 2021
- CVE-2020-3562840Plan
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
CriticalCVSS 9.8No exploitEPSS 3%cgal · computational geometry algorithms libraryMar 4, 2021
- CVE-2020-2863640Plan
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
CriticalCVSS 9.8No exploitEPSS 3%cgal · computational geometry algorithms libraryMar 4, 2021
- CVE-2020-2748340Plan
Garmin Forerunner 235 before 8.20 is affected by: Array index error.
CriticalCVSS 9.9No exploitEPSS 2%garmin · forerunner 235 firmwareNov 16, 2020
- CVE-2019-1578440Plan
Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.
CriticalCVSS 9.8No exploitEPSS 2%srtalliance · secure reliable transportAug 29, 2019
- CVE-2020-2748540Plan
Garmin Forerunner 235 before 8.20 is affected by: Array index error.
CriticalCVSS 9.9No exploitEPSS 2%garmin · forerunner 235 firmwareNov 16, 2020
- CVE-2020-1202240Plan
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
CriticalCVSS 9.8No exploitEPSS 2%advantech · webaccessMay 8, 2020
- CVE-2024-2456339Monitor
Vyper array negative index vulnerability
CriticalCVSS 9.8No exploitEPSS 2%vyperlang · vyperFeb 7, 2024
- CVE-2021-4754839Monitor
ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()
CriticalCVSS 9.8No exploitEPSS 1%linux · linux kernelMay 24, 2024
- CVE-2014-1004839Monitor
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MS
CriticalCVSS 9.8No exploitEPSS 1%qualcomm · mdm9206 firmwareApr 18, 2018
- CVE-2016-1045439Monitor
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE API
CriticalCVSS 9.8No exploitEPSS 1%qualcomm · sd 425 firmwareApr 18, 2018
- CVE-2014-998939Monitor
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD
CriticalCVSS 9.8No exploitEPSS 1%qualcomm · mdm9206 firmwareApr 18, 2018
- CVE-2014-999039Monitor
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD
CriticalCVSS 9.8No exploitEPSS 1%qualcomm · mdm9206 firmwareApr 18, 2018
- CVE-2022-2610039Monitor
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive.
CriticalCVSS 9.8No exploitEPSS 1%sap · sapcarMar 10, 2022
- CVE-2023-2800439Monitor
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial o
CriticalCVSS 9.8No exploitEPSS 1%schneider-electric · powerlogic hdpm6000 firmwareApr 18, 2023
- CVE-2024-3158139Monitor
FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c.
CriticalCVSS 9.8No exploitEPSS 1%ffmpeg · ffmpegApr 17, 2024