VYPR

CWE-129

Improper Validation of Array Index

VariantDraftLikelihood: High

Description

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-100

CVEs mapped to this weakness (641)

page 28 of 33
  • CVE-2024-21493MedFeb 17, 2024
    risk 0.35cvss 5.3epss 0.01

    All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access…

  • CVE-2022-38072MedApr 3, 2023
    risk 0.35cvss 6.5epss 0.01

    An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this…

  • CVE-2020-29245MedDec 28, 2020
    risk 0.35cvss 6.5epss 0.01

    dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData.

  • CVE-2020-29244MedDec 28, 2020
    risk 0.35cvss 6.5epss 0.01

    dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.

  • CVE-2020-29243MedDec 28, 2020
    risk 0.35cvss 6.5epss 0.01

    dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame.

  • CVE-2020-29242MedDec 28, 2020
    risk 0.35cvss 6.5epss 0.01

    dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame.

  • CVE-2020-15112MedAug 5, 2020
    risk 0.35cvss 6.5epss 0.01

    In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd consensus participant could go…

  • CVE-2019-1837MedApr 18, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to improper validation of input…

  • CVE-2026-85084MedSep 3, 2026
    risk 0.34cvss 6.3epss 0.00

    Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers.

  • CVE-2024-53009MedJul 8, 2025
    risk 0.34cvss 5.3epss 0.00

    Memory corruption while operating the mailbox in Automotive.

  • CVE-2023-31194MedJul 5, 2023
    risk 0.34cvss 5.3epss 0.00

    An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2022-42255MedDec 30, 2022
    risk 0.34cvss 5.3epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering.

  • CVE-2022-42254MedDec 30, 2022
    risk 0.34cvss 5.3epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure.

  • CVE-2026-49282MedAug 14, 2026
    risk 0.33cvss 5.1epss 0.00

    Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing instruction-name tables, but the M68K…

  • CVE-2026-46377MedJul 16, 2026
    risk 0.33cvss 6.2epss 0.00

    Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go increments past a trailing backslash in a quoted string such as "\…

  • CVE-2026-45624MedJun 10, 2026
    risk 0.33cvss 5.1epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments. This issue has…

  • CVE-2025-54645MedAug 6, 2025
    risk 0.33cvss 5.0epss 0.00

    Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-30077MedMar 16, 2025
    risk 0.33cvss 6.2epss 0.00

    Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits.

  • CVE-2024-51517MedNov 5, 2024
    risk 0.33cvss 5.1epss 0.00

    Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2014-4616MedAug 24, 2017
    risk 0.32cvss 5.9epss 0.08

    Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.