CWE-129
603 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CVEs (603)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nvidia 3Cloud Gaming Gpu Display DriverVirtual GpuJun 17, 2026 Dec 30, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure. |
If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101. |
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index...Show more |
1Qualcomm 58Aqt1000 Firmware Mdm9150 FirmwareQca6390 Firmware+55 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in camera due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables |
1Qualcomm 197Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+194 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industria...Show more |
2Op Tee Trustedfirmware2Op Tee Op Tee OsJun 17, 2026 Nov 29, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper Validation of Array Index vulnerability. The function `cleanup_shm_ref...Show more |
1Qualcomm 185Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+182 moreJun 17, 2026 Oct 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Sn...Show more |
2Fedoraproject Freedesktop2Dbus FedoraJun 17, 2026 Oct 10, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a me...Show more |
1Qualcomm 152Apq8096au Firmware Aqt1000 FirmwareAr8031 Firmware+149 moreJun 17, 2026 Sep 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectiv...Show more |
1Qualcomm 2Sa8540p Firmware Sa9000p FirmwareJun 17, 2026 Sep 2, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto |
3Netapp SplunkSqlite3Ontap Select Deploy Administration Utility SqliteUniversal ForwarderJun 17, 2026 Aug 3, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. |
Akashi is an open source server implementation of the Attorney Online video game based on the Ace Attorney universe. Affected versions of Akashi are subject to a denial of service attack. An attacker can use a specially...Show more |
NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned IpSecDxe global data can exploit improper validation of an array index to cause code execution, whic...Show more |
1Qualcomm 26Qam8295p Firmware Qca6391 FirmwareQca6696 Firmware+23 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Memory corruption in DSP service due to improper validation of input parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
1Qualcomm 44Apq8053 Firmware Msm8953 FirmwareQca6390 Firmware+41 moreJun 17, 2026 Jun 14, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 An array index is improperly used to lock and unlock a mutex which can lead to a Use After Free condition In the Synx driver in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
1Qualcomm 82Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+79 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Musi...Show more |
Janet before 1.22.0 mishandles arrays. |
2Cgal Debian2Computational Geometry Algorithms Library Debian LinuxJun 17, 2026 Apr 18, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lea...Show more |
2Cgal Debian2Computational Geometry Algorithms Library Debian LinuxJun 17, 2026 Apr 18, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lea...Show more |
2Cgal Debian2Computational Geometry Algorithms Library Debian LinuxJun 17, 2026 Apr 18, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lea...Show more |