VYPR

CWE-118

Incorrect Access of Indexable Resource ('Range Error')

ClassIncomplete

Description

The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-14 · CAPEC-24 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-8 · CAPEC-9

CVEs mapped to this weakness (25)

page 2 of 2
  • CVE-2019-6130MedJan 11, 2019
    risk 0.36cvss 5.5epss 0.02

    Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.

  • CVE-2022-38072MedApr 3, 2023
    risk 0.35cvss 6.5epss 0.01

    An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this…

  • CVE-2017-0302MedMay 9, 2017
    risk 0.35cvss 5.3epss 0.01

    In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if the length of the requested URL is less than 16 characters.

  • CVE-2025-54628MedAug 6, 2025
    risk 0.34cvss 5.3epss 0.00

    Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-50367HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.