CWE-129
569 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CVEs (569)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 40Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+37 moreNov 21, 2024 Jan 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Buffer overflow can occur while processing clip due to lack of check of object size before parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snap...Show more |
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes. |
1Apple 6Icloud Iphone OsItunes+3 moreNov 21, 2024 Dec 18, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Process...Show more |
1Qualcomm 16Apq8096au Firmware Ipq4019 FirmwareIpq8064 Firmware+13 moreNov 21, 2024 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Out of bound access can occur while processing firmware event due to lack of validation of WMI message received from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, S...Show more |
1Qualcomm 13Apq8096au Firmware Ipq4019 FirmwareIpq8064 Firmware+10 moreNov 21, 2024 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Out of bound access occurs while handling the WMI FW event due to lack of check of buffer argument which comes directly from the WLAN FW in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consum...Show more |
1Qualcomm 54Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+51 moreNov 21, 2024 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile...Show more |
1Qualcomm 55Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+52 moreNov 21, 2024 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & M...Show more |
1Huawei 2Nova 5 Firmware Nova 5i Pro FirmwareNov 21, 2024 Nov 29, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Nova 5i pro and Nova 5 smartphones with versions earlier than 9.1.1.190(C00E190R6P2)and Versions earlier than 9.1.1.175(C00E170R3P2) have an improper validation of array index vulnerability. The system does not properly...Show more |
1Qualcomm 15Mdm9205 Firmware Qcs404 FirmwareQcs605 Firmware+12 moreNov 21, 2024 Nov 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,...Show more |
1Qualcomm 27Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+24 moreNov 21, 2024 Nov 21, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Out-of-bounds access can occur in camera driver due to improper validation of array index in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon M...Show more |
NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin, in which an input index value is incorrectly validated, which may lead to denial of service. |
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the product uses untrusted input when calculating or using an array ind...Show more |
1Qualcomm 44Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+41 moreNov 21, 2024 Nov 6, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Out of boundary access due to token received from ADSP and is used without validation as an index into the array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,...Show more |
1Qualcomm 50Mdm9150 Firmware Mdm9607 FirmwareMdm9615 Firmware+47 moreNov 21, 2024 Nov 6, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Improper validation of array index causes OOB write and then leads to memory corruption in MMCP in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobil...Show more |
1Qualcomm 39Mdm9206 Firmware Mdm9607 FirmwareMsm8909w Firmware+36 moreNov 21, 2024 Nov 6, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Out of bound access due to improper validation of array index cause the index table entry to get corrupt in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snap...Show more |
1Qualcomm 48Ipq4019 Firmware Ipq8064 FirmwareIpq8074 Firmware+45 moreNov 21, 2024 Nov 6, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Payload size is not checked before using it as array index in audio in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,...Show more |
Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP input linearly using a...Show more |
1Qualcomm 8Ipq4019 Firmware Ipq8064 FirmwareIpq8074 Firmware+5 moreNov 21, 2024 Sep 30, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper validation of read and write index of tx and rx fifo`s before using for data copy from fifo can lead to out-of-bound access. in Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Ne...Show more |
2Debian Videolan2Debian Linux Vlc Media PlayerNov 21, 2024 Aug 29, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file. |
1Srtalliance 1Secure Reliable Transport Nov 21, 2024 Aug 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections. |