CWE-129
Improper Validation of Array Index
Description
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-100
CVEs mapped to this weakness (609)
page 25 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-29458 | Med | 0.38 | 5.9 | 0.01 | Jul 13, 2023 | Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use. | ||
| CVE-2020-11294 | Med | 0.38 | 5.9 | 0.00 | May 7, 2021 | Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2015-8316 | Med | 0.38 | 5.9 | 0.02 | Sep 6, 2017 | Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address. | ||
| CVE-2005-0369 | Med | 0.38 | 5.3 | 0.04 | May 2, 2005 | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array. | ||
| CVE-2026-45359 | Med | 0.37 | 5.7 | 0.00 | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-22, an invalid connected-components:keep-top value could result in a heap buffer over-read when performing the connected components operation.… | ||
| CVE-2026-26932 | Med | 0.37 | 5.7 | 0.00 | Feb 26, 2026 | Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process.… | ||
| CVE-2024-35164 | Med | 0.37 | 6.8 | 0.00 | Jul 2, 2025 | The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes could allow… | ||
| CVE-2025-39728 | Med | 0.36 | 5.5 | 0.00 | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init() With UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due to dereferencing `ctx->clk_data.hws` before setting `ctx->clk_data.num = nr_clks`. Move that up to… | ||
| CVE-2024-49970 | Med | 0.36 | 5.5 | 0.00 | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Implement bounds check for stream encoder creation in DCN401 'stream_enc_regs' array is an array of dcn10_stream_enc_registers structures. The array is initialized with four elements,… | ||
| CVE-2024-32673 | Med | 0.36 | 5.5 | 0.00 | Jul 3, 2024 | Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segmentation fault issue. This issue affects Walrus: before 72c7230f32a0b791355bbdfc78669701024b0956. | ||
| CVE-2023-52728 | Med | 0.36 | 5.5 | 0.00 | Apr 30, 2024 | Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString. | ||
| CVE-2024-26758 | Med | 0.36 | 5.5 | 0.00 | Apr 3, 2024 | In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore suspended array in md_check_recovery() mddev_suspend() never stop sync_thread, hence it doesn't make sense to ignore suspended array in md_check_recovery(), which might cause sync_thread can't… | ||
| CVE-2023-33111 | Med | 0.36 | 5.5 | 0.00 | Apr 1, 2024 | Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. | ||
| CVE-2020-36776 | Med | 0.36 | 5.5 | 0.00 | Feb 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/cpufreq_cooling: Fix slab OOB issue Slab OOB issue is scanned by KASAN in cpu_power_to_freq(). If power is limited below the power of OPP0 in EM table, it will cause slab out-of-bound issue… | ||
| CVE-2022-47348 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services. | ||
| CVE-2022-47347 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services. | ||
| CVE-2022-47346 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services. | ||
| CVE-2022-47345 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services. | ||
| CVE-2022-47344 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services. | ||
| CVE-2022-47343 | Med | 0.36 | 5.5 | 0.00 | Feb 12, 2023 | In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services. |
- risk 0.38cvss 5.9epss 0.01
Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use.
- risk 0.38cvss 5.9epss 0.00
Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.38cvss 5.9epss 0.02
Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.
- risk 0.38cvss 5.3epss 0.04
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.
- risk 0.37cvss 5.7epss 0.00
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-22, an invalid connected-components:keep-top value could result in a heap buffer over-read when performing the connected components operation.…
- risk 0.37cvss 5.7epss 0.00
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process.…
- risk 0.37cvss 6.8epss 0.00
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes could allow…
- risk 0.36cvss 5.5epss 0.00
In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init() With UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due to dereferencing `ctx->clk_data.hws` before setting `ctx->clk_data.num = nr_clks`. Move that up to…
- risk 0.36cvss 5.5epss 0.00
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Implement bounds check for stream encoder creation in DCN401 'stream_enc_regs' array is an array of dcn10_stream_enc_registers structures. The array is initialized with four elements,…
- risk 0.36cvss 5.5epss 0.00
Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segmentation fault issue. This issue affects Walrus: before 72c7230f32a0b791355bbdfc78669701024b0956.
- risk 0.36cvss 5.5epss 0.00
Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString.
- risk 0.36cvss 5.5epss 0.00
In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore suspended array in md_check_recovery() mddev_suspend() never stop sync_thread, hence it doesn't make sense to ignore suspended array in md_check_recovery(), which might cause sync_thread can't…
- risk 0.36cvss 5.5epss 0.00
Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command.
- risk 0.36cvss 5.5epss 0.00
In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/cpufreq_cooling: Fix slab OOB issue Slab OOB issue is scanned by KASAN in cpu_power_to_freq(). If power is limited below the power of OPP0 in EM table, it will cause slab out-of-bound issue…
- risk 0.36cvss 5.5epss 0.00
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
- risk 0.36cvss 5.5epss 0.00
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
- risk 0.36cvss 5.5epss 0.00
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
- risk 0.36cvss 5.5epss 0.00
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
- risk 0.36cvss 5.5epss 0.00
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
- risk 0.36cvss 5.5epss 0.00
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.