VYPR

CWE-129

Improper Validation of Array Index

VariantDraftLikelihood: High

Description

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-100

CVEs mapped to this weakness (641)

page 31 of 33
  • CVE-2026-50144HigJul 15, 2026
    risk 0.00cvss 7.1epss 0.00

    ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows an out-of-bounds heap write in ncnn::ParamDict::load_param() when Net::load_param() loads a malicious…

  • CVE-2026-24238HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-57251HigJul 8, 2026
    risk 0.00cvss 7.8epss 0.00

    The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper limit and consistency checks. Out-of-bounds access to the underlying array is exposed, ultimately leading to a crash of the application.

  • CVE-2026-57272HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57271HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57270HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57269HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57268HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57267HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57266HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57265HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-57264HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-13132HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-13131HigJul 2, 2026
    risk 0.00cvss 8.3epss 0.00

    GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces…

  • CVE-2026-14193HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    DVP80ES300T with Improper Validation of Array Index Vulnerability

  • CVE-2026-14191HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value…

  • CVE-2026-22879HigJun 25, 2026
    risk 0.00cvss 8.1epss 0.00

    vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

  • CVE-2026-30984MedMar 10, 2026
    risk 0.00cvss 6.1epss 0.00

    iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap out-of-bounds read in CIccCalculatorFunc::ApplySequence() causing an application crash. This vulnerability is fixed in 2.3.1.5.

  • CVE-2026-30982MedMar 10, 2026
    risk 0.00cvss 6.1epss 0.00

    iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap out-of-bounds read in CIccPcsXform::pushXYZConvert() causing crash and potentially leaking memory contents. This vulnerability is fixed in 2.3.1.5.

  • CVE-2025-69248HigFeb 23, 2026
    risk 0.00cvss 7.5epss 0.01

    free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of free5GC's AMF service have a Buffer Overflow vulnerability leading to Denial of Service. Remote unauthenticated attackers can crash the AMF service by sending a…