VYPR

CWE-129

Improper Validation of Array Index

VariantDraftLikelihood: High

Description

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-100

CVEs mapped to this weakness (609)

page 23 of 31
  • CVE-2023-21650MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.

  • CVE-2022-33281MedMay 2, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending any frames.

  • CVE-2022-33302MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.

  • CVE-2022-33289MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

  • CVE-2023-20633MedMar 7, 2023
    risk 0.44cvss 6.7epss 0.00

    In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628508; Issue ID: ALPS07628508.

  • CVE-2022-25711MedDec 13, 2022
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in camera due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-35121MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    An array index is improperly used to lock and unlock a mutex which can lead to a Use After Free condition In the Synx driver in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30325MedFeb 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…

  • CVE-2020-11308MedMar 17, 2021
    risk 0.44cvss 6.8epss 0.00

    Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2018-10120HigApr 16, 2018
    risk 0.44cvss 7.8epss 0.02

    The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overflow with write access) or…

  • CVE-2026-40886HigApr 23, 2026
    risk 0.43cvss 7.7epss 0.00

    Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed…

  • CVE-2025-54644MedAug 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54643MedAug 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52819MedMay 21, 2024
    risk 0.43cvss 6.6epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga For pptable structs that use flexible array sizes, use flexible arrays.

  • CVE-2026-52856HigJul 31, 2026
    risk 0.42cvss 7.5epss 0.00

    Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

  • CVE-2026-45799HigJul 17, 2026
    risk 0.42cvss 7.5epss 0.01

    Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate that a LENGTH_DELIMITED field length is non-negative before skip(),…

  • CVE-2026-56770HigJun 25, 2026
    risk 0.42cvss 7.5epss 0.00

    libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine…

  • CVE-2026-32682MedJun 17, 2026
    risk 0.42cvss 6.5epss 0.00

    When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations containing backendRef…

  • CVE-2026-41643HigMay 7, 2026
    risk 0.42cvss 7.5epss 0.01

    GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic.…

  • CVE-2026-32285HigMar 26, 2026
    risk 0.42cvss 7.5epss 0.01

    The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.