CWE-129
569 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CVEs (569)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services. |
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services. |
An Improper Validation of Array Index vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX 5000 Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an attacker sen...Show more |
An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemon (aftmand) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause...Show more |
1Qualcomm 11Qam8295p Firmware Qca6574au FirmwareQca6696 Firmware+8 moreApr 9, 2025 Jan 9, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in android core due to improper validation of array index while returning feature ids after license authentication. |
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering. |
1Nvidia 3Cloud Gaming Gpu Display DriverVirtual GpuNov 21, 2024 Dec 30, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure. |
If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101. |
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index...Show more |
1Qualcomm 58Aqt1000 Firmware Mdm9150 FirmwareQca6390 Firmware+55 moreApr 22, 2025 Dec 13, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in camera due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables |
1Qualcomm 197Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+194 moreApr 22, 2025 Dec 13, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industria...Show more |
OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper Validation of Array Index vulnerability. The function `cleanup_shm_ref...Show more |
1Qualcomm 185Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+182 moreMay 9, 2025 Oct 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Sn...Show more |
2Fedoraproject Freedesktop2Dbus FedoraJun 9, 2025 Oct 10, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a me...Show more |
1Qualcomm 152Apq8096au Firmware Aqt1000 FirmwareAr8031 Firmware+149 moreNov 21, 2024 Sep 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectiv...Show more |
1Qualcomm 2Sa8540p Firmware Sa9000p FirmwareNov 21, 2024 Sep 2, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto |
3Netapp SplunkSqlite3Ontap Select Deploy Administration Utility SqliteUniversal ForwarderFeb 13, 2026 Aug 3, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. |
Akashi is an open source server implementation of the Attorney Online video game based on the Ace Attorney universe. Affected versions of Akashi are subject to a denial of service attack. An attacker can use a specially...Show more |
NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned IpSecDxe global data can exploit improper validation of an array index to cause code execution, whic...Show more |
1Qualcomm 26Qam8295p Firmware Qca6391 FirmwareQca6696 Firmware+23 moreNov 21, 2024 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Memory corruption in DSP service due to improper validation of input parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |