CWE-129 · 609 записей
Improper Validation of Array Index
CVE этого класса
610 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
66На этой неделе | CVE-2022-48503Готовый эксплойт | The issue was addressed with improved bounds checks.apple · safari · CWE-129 | Высокая8,8 | KEV | 3,2 % | 14 авг. 2023 г. |
43В плане | CVE-2023-0755Эксплойта нет | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotege · digital industrial gateway server · CWE-129 | Критическая9,8 | — | 11,8 % | 23 февр. 2023 г. |
41В плане | CVE-2021-35592Эксплойта нет | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).oracle · mysql cluster · CWE-129 | Средняя6,3 | — | 52,5 % | 20 окт. 2021 г. |
41В плане | CVE-2016-9053Эксплойта нет | An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3.aerospike · database server · CWE-129 | Критическая9,8 | — | 7,2 % | 21 февр. 2017 г. |
41В плане | CVE-2015-8366Эксплойта нет | Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and posslibraw · libraw · CWE-129 | Критическая9,8 | — | 5,1 % | 14 янв. 2020 г. |
40В плане | CVE-2021-35598Эксплойта нет | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).oracle · mysql cluster · CWE-129 | Средняя6,3 | — | 51,1 % | 20 окт. 2021 г. |
40В плане | CVE-2021-35594Эксплойта нет | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).oracle · mysql cluster · CWE-129 | Средняя6,3 | — | 51,1 % | 20 окт. 2021 г. |
40В плане | CVE-2020-35636Эксплойта нет | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_pcgal · computational geometry algorithms library · CWE-129 | Критическая9,8 | — | 3,3 % | 4 мар. 2021 г. |
40В плане | CVE-2019-17212Эксплойта нет | Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0.mbed · mbed · CWE-129 | Критическая9,8 | — | 3,1 % | 5 нояб. 2019 г. |
40В плане | CVE-2020-28601Эксплойта нет | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.cgal · computational geometry algorithms library · CWE-129 | Критическая9,8 | — | 2,9 % | 4 мар. 2021 г. |
40В плане | CVE-2020-35628Эксплойта нет | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.cgal · computational geometry algorithms library · CWE-129 | Критическая9,8 | — | 2,9 % | 4 мар. 2021 г. |
40В плане | CVE-2020-28636Эксплойта нет | A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.cgal · computational geometry algorithms library · CWE-129 | Критическая9,8 | — | 2,9 % | 4 мар. 2021 г. |
40В плане | CVE-2020-27483Эксплойта нет | Garmin Forerunner 235 before 8.20 is affected by: Array index error.garmin · forerunner 235 firmware · CWE-129 | Критическая9,9 | — | 2,1 % | 16 нояб. 2020 г. |
40В плане | CVE-2019-15784Эксплойта нет | Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.srtalliance · secure reliable transport · CWE-129 | Критическая9,8 | — | 2,0 % | 29 авг. 2019 г. |
40В плане | CVE-2020-27485Эксплойта нет | Garmin Forerunner 235 before 8.20 is affected by: Array index error.garmin · forerunner 235 firmware · CWE-129 | Критическая9,9 | — | 1,7 % | 16 нояб. 2020 г. |
40В плане | CVE-2020-12022Эксплойта нет | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.advantech · webaccess · CWE-129 | Критическая9,8 | — | 1,7 % | 8 мая 2020 г. |
39Наблюдать | CVE-2024-24563Эксплойта нет | Vyper array negative index vulnerabilityvyperlang · vyper · CWE-129 | Критическая9,8 | — | 1,5 % | 7 февр. 2024 г. |
39Наблюдать | CVE-2021-47548Эксплойта нет | ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()linux · linux kernel · CWE-129 | Критическая9,8 | — | 1,4 % | 24 мая 2024 г. |
39Наблюдать | CVE-2014-9989Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDqualcomm · mdm9206 firmware · CWE-129 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2014-9990Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDqualcomm · mdm9206 firmware · CWE-129 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2014-10048Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSqualcomm · mdm9206 firmware · CWE-129 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2016-10454Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE APIqualcomm · sd 425 firmware · CWE-129 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
39Наблюдать | CVE-2022-26100Эксплойта нет | SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive.sap · sapcar · CWE-129 | Критическая9,8 | — | 1,2 % | 10 мар. 2022 г. |
39Наблюдать | CVE-2023-28004Эксплойта нет | A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial oschneider-electric · powerlogic hdpm6000 firmware · CWE-129 | Критическая9,8 | — | 1,1 % | 18 апр. 2023 г. |
39Наблюдать | CVE-2020-3633Эксплойта нет | Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allocated or not in Snapqualcomm · apq8009 firmware · CWE-129 | Критическая9,8 | — | 1,1 % | 2 июн. 2020 г. |
- CVE-2022-4850366На этой неделе
The issue was addressed with improved bounds checks.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 3 %apple · safari14 авг. 2023 г.
- CVE-2023-075543В плане
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remote
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %ge · digital industrial gateway server23 февр. 2023 г.
- CVE-2021-3559241В плане
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).
СредняяCVSS 6,3Эксплойта нетEPSS 52 %oracle · mysql cluster20 окт. 2021 г.
- CVE-2016-905341В плане
An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %aerospike · database server21 февр. 2017 г.
- CVE-2015-836641В плане
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and poss
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %libraw · libraw14 янв. 2020 г.
- CVE-2021-3559840В плане
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).
СредняяCVSS 6,3Эксплойта нетEPSS 51 %oracle · mysql cluster20 окт. 2021 г.
- CVE-2021-3559440В плане
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).
СредняяCVSS 6,3Эксплойта нетEPSS 51 %oracle · mysql cluster20 окт. 2021 г.
- CVE-2020-3563640В плане
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_p
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cgal · computational geometry algorithms library4 мар. 2021 г.
- CVE-2019-1721240В плане
Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mbed · mbed5 нояб. 2019 г.
- CVE-2020-2860140В плане
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cgal · computational geometry algorithms library4 мар. 2021 г.
- CVE-2020-3562840В плане
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cgal · computational geometry algorithms library4 мар. 2021 г.
- CVE-2020-2863640В плане
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cgal · computational geometry algorithms library4 мар. 2021 г.
- CVE-2020-2748340В плане
Garmin Forerunner 235 before 8.20 is affected by: Array index error.
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %garmin · forerunner 235 firmware16 нояб. 2020 г.
- CVE-2019-1578440В плане
Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %srtalliance · secure reliable transport29 авг. 2019 г.
- CVE-2020-2748540В плане
Garmin Forerunner 235 before 8.20 is affected by: Array index error.
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %garmin · forerunner 235 firmware16 нояб. 2020 г.
- CVE-2020-1202240В плане
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %advantech · webaccess8 мая 2020 г.
- CVE-2024-2456339Наблюдать
Vyper array negative index vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %vyperlang · vyper7 февр. 2024 г.
- CVE-2021-4754839Наблюдать
ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %linux · linux kernel24 мая 2024 г.
- CVE-2014-998939Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9206 firmware18 апр. 2018 г.
- CVE-2014-999039Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9206 firmware18 апр. 2018 г.
- CVE-2014-1004839Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MS
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9206 firmware18 апр. 2018 г.
- CVE-2016-1045439Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, and SD 625, in a QTEE API
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · sd 425 firmware18 апр. 2018 г.
- CVE-2022-2610039Наблюдать
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sap · sapcar10 мар. 2022 г.
- CVE-2023-2800439Наблюдать
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial o
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %schneider-electric · powerlogic hdpm6000 firmware18 апр. 2023 г.
- CVE-2020-363339Наблюдать
Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allocated or not in Snap
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · apq8009 firmware2 июн. 2020 г.