CWE-129
603 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
CVEs (603)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 30Mdm9206 Firmware Mdm9607 FirmwareMdm9640 Firmware+27 moreJun 17, 2026 Jun 14, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Out of bounds read occurs due to improper validation of array while processing VDEV stop response from WLAN firmware in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobi...Show more |
1Qualcomm 18Mdm9206 Firmware Mdm9607 FirmwareMdm9640 Firmware+15 moreJun 17, 2026 Jun 14, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Buffer overflow in WLAN driver event handlers due to improper validation of array index in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9206, MDM9...Show more |
1Qualcomm 46Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+43 moreNov 21, 2024 Jun 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Out of bounds memory read and access due to improper array index validation may lead to unexpected behavior while decoding XTRA file in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jun 12, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim s...Show more |
1Qualcomm 26Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+23 moreNov 21, 2024 May 24, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper input validation on input which is used as an array index will lead to an out of bounds issue while processing AP find event from firmware in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdr...Show more |
1Qualcomm 16Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+13 moreNov 21, 2024 May 6, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 While iterating through the models contained in a fixed-size array in the actData structure, which also stores an incorrect number of models that is greater than the size of the array, a buffer overflow occurs in Snapdra...Show more |
1Cisco 1Unified Communications Manager Jun 17, 2026 Apr 18, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI....Show more |
In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a hea...Show more |
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) create context command DDI DxgkDdiCreateContext in which the product uses untrusted input when calculating or using an ar...Show more |
1Qualcomm 41Mdm9150 Firmware Mdm9206 FirmwareMdm9607 Firmware+38 moreNov 21, 2024 Feb 25, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper validation of array index can lead to unauthorized access while processing debugFS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Mu...Show more |
1Qualcomm 30Msm8996au Firmware Qcs605 FirmwareSd 410 Firmware+27 moreNov 21, 2024 Feb 25, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Exceeding the limit of usage entries are not tracked and the information will be lost causing the content to lose continuity in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronic...Show more |
1Sound Exchange Project 1Sound Exchange Jun 17, 2026 Feb 15, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buffer overflow. |
1Qualcomm 35Mdm9206 Firmware Mdm9607 FirmwareMdm9640 Firmware+32 moreNov 21, 2024 Feb 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 While processing radio connection status change events, Radio index is not properly validated in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdra...Show more |
FFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can result in Denial of service. This attack appears to be exploitable via specially crafted AV1 file h...Show more |
1Qualcomm 20Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+17 moreNov 21, 2024 Jan 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible undefined behavior due to lack of size check in function for parameter segment_idx can lead to a read outside of the intended region in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MD...Show more |
3Apple CanonicalWebkitgtk7Iphone Os ItunesSafari+4 moreNov 21, 2024 Jan 11, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed w...Show more |
2Google Redhat4Chrome Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Jan 9, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An improper update of the WebAssembly dispatch table in WebAssembly in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. |
1Qualcomm 16Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+13 moreNov 21, 2024 Nov 28, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 When a malformed command is sent to the device programmer, an out-of-bounds access can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MDM9655, MSM8909W, MSM89...Show more |
1Qualcomm 14Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+11 moreJun 17, 2026 Oct 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper input validation in TZ led to array out of bound in TZ function while accessing the peripheral details using the incoming data in Snapdragon Mobile, Snapdragon Wear version MDM9206, MDM9607, MDM9650, SD 210/SD 2...Show more |
1Qualcomm 2Sd 845 Firmware Sd 850 FirmwareNov 21, 2024 Oct 26, 2018 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 A micro-core of QMP transportation may cause a macro-core to read from or write to arbitrary memory in Snapdragon Mobile in version SD 845, SD 850. |