CWE-129
Improper Validation of Array Index
Description
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-100
CVEs mapped to this weakness (641)
page 28 of 33| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21493 | Med | 0.35 | 5.3 | 0.01 | Feb 17, 2024 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access… | ||
| CVE-2022-38072 | Med | 0.35 | 6.5 | 0.01 | Apr 3, 2023 | An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this… | ||
| CVE-2020-29245 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData. | ||
| CVE-2020-29244 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame. | ||
| CVE-2020-29243 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame. | ||
| CVE-2020-29242 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2020 | dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame. | ||
| CVE-2020-15112 | Med | 0.35 | 6.5 | 0.01 | Aug 5, 2020 | In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd consensus participant could go… | ||
| CVE-2019-1837 | Med | 0.35 | 5.3 | 0.02 | Apr 18, 2019 | A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to improper validation of input… | ||
| CVE-2026-85084 | Med | 0.34 | 6.3 | 0.00 | Sep 3, 2026 | Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers. | ||
| CVE-2024-53009 | Med | 0.34 | 5.3 | 0.00 | Jul 8, 2025 | Memory corruption while operating the mailbox in Automotive. | ||
| CVE-2023-31194 | Med | 0.34 | 5.3 | 0.00 | Jul 5, 2023 | An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability. | ||
| CVE-2022-42255 | Med | 0.34 | 5.3 | 0.00 | Dec 30, 2022 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering. | ||
| CVE-2022-42254 | Med | 0.34 | 5.3 | 0.00 | Dec 30, 2022 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure. | ||
| CVE-2026-49282 | Med | 0.33 | 5.1 | 0.00 | Aug 14, 2026 | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing instruction-name tables, but the M68K… | ||
| CVE-2026-46377 | Med | 0.33 | 6.2 | 0.00 | Jul 16, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go increments past a trailing backslash in a quoted string such as "\… | ||
| CVE-2026-45624 | Med | 0.33 | 5.1 | 0.00 | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments. This issue has… | ||
| CVE-2025-54645 | Med | 0.33 | 5.0 | 0.00 | Aug 6, 2025 | Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-30077 | Med | 0.33 | 6.2 | 0.00 | Mar 16, 2025 | Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits. | ||
| CVE-2024-51517 | Med | 0.33 | 5.1 | 0.00 | Nov 5, 2024 | Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2014-4616 | Med | 0.32 | 5.9 | 0.08 | Aug 24, 2017 | Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function. |
- risk 0.35cvss 5.3epss 0.01
All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access…
- risk 0.35cvss 6.5epss 0.01
An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this…
- risk 0.35cvss 6.5epss 0.01
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData.
- risk 0.35cvss 6.5epss 0.01
dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.
- risk 0.35cvss 6.5epss 0.01
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame.
- risk 0.35cvss 6.5epss 0.01
dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame.
- risk 0.35cvss 6.5epss 0.01
In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd consensus participant could go…
- risk 0.35cvss 5.3epss 0.02
A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to improper validation of input…
- risk 0.34cvss 6.3epss 0.00
Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers.
- risk 0.34cvss 5.3epss 0.00
Memory corruption while operating the mailbox in Automotive.
- risk 0.34cvss 5.3epss 0.00
An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.
- risk 0.34cvss 5.3epss 0.00
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering.
- risk 0.34cvss 5.3epss 0.00
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure.
- risk 0.33cvss 5.1epss 0.00
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing instruction-name tables, but the M68K…
- risk 0.33cvss 6.2epss 0.00
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go increments past a trailing backslash in a quoted string such as "\…
- risk 0.33cvss 5.1epss 0.00
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments. This issue has…
- risk 0.33cvss 5.0epss 0.00
Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.33cvss 6.2epss 0.00
Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits.
- risk 0.33cvss 5.1epss 0.00
Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.32cvss 5.9epss 0.08
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.