CWE-118
25 CVEs • Abstraction: Class
Incorrect Access of Indexable Resource ('Range Error')
The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.
CVEs (25)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Jumio SDK before 1.5.0 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function. |
H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors. |
In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in rollback protection. |
1F5 1Big Ip Access Policy Manager May 13, 2026 May 9, 2017 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if the length of the requested URL is less th...Show more |
2Fedoraproject Gnome2Fedora Gtk VncMay 13, 2026 Feb 28, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyr...Show more |