← Back
CWE-129

603 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Improper Validation of Array Index

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

JSON object

Loading...

CVEs (603)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
285315 5g Iot Firmware
Aqt1000 FirmwareAr8031 Firmware+282 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while handling command through WMI interfaces.
1Qualcomm
2929205 Lte Firmware
Apq8017 FirmwareApq8064au Firmware+289 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
1Qualcomm
195315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+192 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
1Qualcomm
273315 5g Iot Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+270 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
1Qualcomm
179Aqt1000 Firmware
Ar8035 FirmwareAr9380 Firmware+176 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
1Qualcomm
51Aqt1000 Firmware
Qca6390 FirmwareQca6391 Firmware+48 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption due to improper validation of array index in Linux while updating adn record.
1Qualcomm
13Snapdragon W5+ Gen 1 Wearable Platform Firmware
Sw5100 FirmwareSw5100p Firmware+10 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption due to improper validation of array index in Audio.
1Qualcomm
259315 5g Iot Modem Firmware
Apq5053 Aa FirmwareAqt1000 Firmware+256 more
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
1Simonwaldherr
1Zplgfa
Jun 17, 2026
Sep 5, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which th...Show more
ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequenceShow less
1Disintegration
1Imaging
Jun 17, 2026
Sep 5, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether th...Show more
disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequenceShow less
1Apple
6Ipados
Iphone OsMacos+3 more
Jun 17, 2026
Aug 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.
1Qualcomm
51Aqt1000 Firmware
Csrb31024 FirmwareQam8295p Firmware+48 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
1Zabbix
1Zabbix
Jun 17, 2026
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is...Show more
Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use.Show less
1Diagon Project
1Diagon
Jun 17, 2026
Jul 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption. A victim would need to open a malicious...Show more
An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.Show less
1Schneider Electric
1Ecostruxure Foxboro Dcs Control Core Services
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using...Show more
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver. Show less
2Debian
Libreoffice
2Debian Linux
Libreoffice
Jun 17, 2026
May 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded...Show more
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as AGGREGATE, could be created with less parameters passed to the formula interpreter than it expected, leading to an array index underflow, in which case there is a risk that arbitrary code could be executed. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.6; 7.5 versions prior to 7.5.1.Show less
1Qualcomm
8Sm8450 Firmware
Wcd9380 FirmwareWcn685x 1 Firmware+5 more
Jun 17, 2026
May 2, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending any frames.
1Schneider Electric
1Powerlogic Hdpm6000 Firmware
Jun 17, 2026
Apr 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial of service or remote code execution.
1Linux
1Linux Kernel
Jun 17, 2026
Apr 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data, which can result in a memory acce...Show more
A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an array. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel.Show less
1Qualcomm
225315 5g Iot Modem Firmware
8905 Firmware8909 Firmware+222 more
Jun 17, 2026
Apr 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.