Skip to content
Noroxi

CWE-129 · 610 records

Improper Validation of Array Index

CVEs in this class

615 records

  • CVE-2022-48503
    66This week

    The issue was addressed with improved bounds checks.

    HighCVSS 8.8KEVWeaponizedEPSS 3%

    apple · safariAug 14, 2023

  • The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remote

    CriticalCVSS 9.8No exploitEPSS 12%

    ge · digital industrial gateway serverFeb 23, 2023

  • Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).

    MediumCVSS 6.3No exploitEPSS 52%

    oracle · mysql clusterOct 20, 2021

  • An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3.

    CriticalCVSS 9.8No exploitEPSS 7%

    aerospike · database serverFeb 21, 2017

  • Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and poss

    CriticalCVSS 9.8No exploitEPSS 5%

    libraw · librawJan 14, 2020

  • Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).

    MediumCVSS 6.3No exploitEPSS 51%

    oracle · mysql clusterOct 20, 2021

  • Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).

    MediumCVSS 6.3No exploitEPSS 51%

    oracle · mysql clusterOct 20, 2021

  • A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_p

    CriticalCVSS 9.8No exploitEPSS 3%

    cgal · computational geometry algorithms libraryMar 4, 2021

  • Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0.

    CriticalCVSS 9.8No exploitEPSS 3%

    mbed · mbedNov 5, 2019

  • A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.

    CriticalCVSS 9.8No exploitEPSS 3%

    cgal · computational geometry algorithms libraryMar 4, 2021

  • A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.

    CriticalCVSS 9.8No exploitEPSS 3%

    cgal · computational geometry algorithms libraryMar 4, 2021

  • A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.

    CriticalCVSS 9.8No exploitEPSS 3%

    cgal · computational geometry algorithms libraryMar 4, 2021

  • Garmin Forerunner 235 before 8.20 is affected by: Array index error.

    CriticalCVSS 9.9No exploitEPSS 2%

    garmin · forerunner 235 firmwareNov 16, 2020

  • Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.

    CriticalCVSS 9.8No exploitEPSS 2%

    srtalliance · secure reliable transportAug 29, 2019

  • Garmin Forerunner 235 before 8.20 is affected by: Array index error.

    CriticalCVSS 9.9No exploitEPSS 2%

    garmin · forerunner 235 firmwareNov 16, 2020

  • Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    advantech · webaccessMay 8, 2020

  • Vyper array negative index vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    vyperlang · vyperFeb 7, 2024

  • ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()

    CriticalCVSS 9.8No exploitEPSS 1%

    linux · linux kernelMay 24, 2024

  • In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MS

    CriticalCVSS 9.8No exploitEPSS 1%

    qualcomm · mdm9206 firmwareApr 18, 2018

  • In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE API

    CriticalCVSS 9.8No exploitEPSS 1%

    qualcomm · sd 425 firmwareApr 18, 2018

  • CVE-2014-9989
    39Monitor

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD

    CriticalCVSS 9.8No exploitEPSS 1%

    qualcomm · mdm9206 firmwareApr 18, 2018

  • CVE-2014-9990
    39Monitor

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD

    CriticalCVSS 9.8No exploitEPSS 1%

    qualcomm · mdm9206 firmwareApr 18, 2018

  • SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive.

    CriticalCVSS 9.8No exploitEPSS 1%

    sap · sapcarMar 10, 2022

  • A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial o

    CriticalCVSS 9.8No exploitEPSS 1%

    schneider-electric · powerlogic hdpm6000 firmwareApr 18, 2023

  • FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c.

    CriticalCVSS 9.8No exploitEPSS 1%

    ffmpeg · ffmpegApr 17, 2024

All vulnerability classes