CWE-129
603 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CVEs (603)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 98Aqt1000 Firmware Csrb31024 FirmwarePm7150a Firmware+95 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible memory corruption in BSI module due to improper validation of parameter count in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile |
1Qualcomm 250Apq8017 Firmware Aqt1000 FirmwareAr8035 Firmware+247 moreJun 17, 2026 Feb 22, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters received from the ePDG server in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snap...Show more |
1Qualcomm 314Apq8076 Aqt1000Ar8031+311 moreJun 17, 2026 Jan 21, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Out of bound write while copying data using IOCTL due to lack of check of array index received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT...Show more |
An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue. |
GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call. |
In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.) |
In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.) |
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData. |
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame. |
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame. |
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame. |
2Stepmania Xiph.org2Libvorbis StepmaniaJun 17, 2026 Dec 26, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146. |
1Garmin 1Forerunner 235 Firmware Jun 17, 2026 Nov 16, 2020 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectIQ application to the...Show more |
1Garmin 1Forerunner 235 Firmware Jun 17, 2026 Nov 16, 2020 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 Garmin Forerunner 235 before 8.20 is affected by: Array index error. The component is: ConnectIQ TVM. The attack vector is: To exploit the vulnerability, the attacker must upload a malicious ConnectIQ application to the...Show more |
1Qualcomm 89Apq8009 Firmware Apq8017 FirmwareApq8037 Firmware+86 moreJun 17, 2026 Nov 12, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 u'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memory overflow' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon I...Show more |
1Qualcomm 19Qsm8350 Firmware Sc7180 FirmwareSdx55 Firmware+16 moreJun 17, 2026 Nov 12, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 u'Incorrect validation of ring context fetched from host memory can lead to memory overflow' in Snapdragon Compute, Snapdragon Mobile in QSM8350, SC7180, SDX55, SDX55M, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, S...Show more |
1Qualcomm 40Agatti Firmware Apq8053 FirmwareApq8096au Firmware+37 moreJun 17, 2026 Nov 2, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check to validate the index length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snap...Show more |
1Qualcomm 41Agatti Firmware Apq8053 FirmwareApq8096au Firmware+38 moreJun 17, 2026 Nov 2, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying into it' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snap...Show more |
1Qualcomm 51Agatti Firmware Apq8009 FirmwareApq8017 Firmware+48 moreJun 17, 2026 Nov 2, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 u'Array index underflow issue in adsp driver due to improper check of channel id before used as array index.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industria...Show more |
1Sized Chunks Project 1Sized Chunks Jun 17, 2026 Sep 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the InlineArray implementation, an unaligned reference may be generated for a type that has a large alignment requirement. |