VYPR

CWE-129

Improper Validation of Array Index

VariantDraftLikelihood: High

Description

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-100

CVEs mapped to this weakness (641)

page 19 of 33
  • CVE-2025-65562HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.01

    The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in…

  • CVE-2025-1975HigMay 16, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a model via the /api/pull…

  • CVE-2024-21522HigJul 10, 2024
    risk 0.49cvss 7.5epss 0.01

    All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to the new OpusDecoder().decode or new OpusDecoder().decodeFloat functions it is not checked for negative values. This can lead to a process crash.

  • CVE-2024-36740HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of size.

  • CVE-2024-36743HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot.

  • CVE-2024-34050HigApr 30, 2024
    risk 0.49cvss 7.5epss 0.01

    Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8 | uint64(b[0])" in reader.go.

  • CVE-2024-23084HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.01

    Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of…

  • CVE-2023-22408HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Validation of Array Index vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX 5000 Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an attacker sends an SIP packets with a malformed SDP field then the SIP…

  • CVE-2023-22401HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemon (aftmand) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On the PTX10008 and PTX10016…

  • CVE-2022-25690HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2022-30763HigMay 16, 2022
    risk 0.49cvss 7.5epss 0.02

    Janet before 1.22.0 mishandles arrays.

  • CVE-2021-39985HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    The HwNearbyMain module has a Improper Validation of Array Index vulnerability.Successful exploitation of this vulnerability may cause a process to restart.

  • CVE-2021-37057HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to restart the phone.

  • CVE-2020-18430HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).

  • CVE-2020-18428HigJul 26, 2021
    risk 0.49cvss 7.5epss 0.01

    tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS).

  • CVE-2021-22374HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Improper Validation of Array Index Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause stability risks.

  • CVE-2020-11226HigMar 17, 2021
    risk 0.49cvss 7.5epss 0.01

    Out of bound memory read in Data modem while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2020-25241HigMar 15, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP RST packages. An attacker could exploit this to terminate arbitrary TCP…

  • CVE-2021-3121HigJan 11, 2021
    risk 0.49cvss 8.6epss 0.03

    An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.

  • CVE-2020-28852HigJan 2, 2021
    risk 0.49cvss 7.5epss 0.02

    In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)