VYPR

CWE-129

Improper Validation of Array Index

VariantDraftLikelihood: High

Description

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-100

CVEs mapped to this weakness (609)

page 7 of 31
  • CVE-2018-11891HigSep 19, 2018
    risk 0.57cvss 8.8epss 0.00

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on the length of array while accessing can lead to an out of bound read in WLAN HOST function.

  • CVE-2018-11263HigSep 6, 2018
    risk 0.57cvss 8.8epss 0.00

    In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is received from the FW and is used to access the buffer to copy the radio stats received for each radio from FW. If the radio_id received from the FW is greater…

  • CVE-2018-11490HigMay 26, 2018
    risk 0.57cvss 8.8epss 0.02

    The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or…

  • CVE-2018-11489HigMay 26, 2018
    risk 0.57cvss 8.8epss 0.03

    The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified…

  • CVE-2023-20080HigMar 23, 2023
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation of data boundaries.…

  • CVE-2017-7228HigApr 4, 2017
    risk 0.56cvss 8.2epss 0.02

    An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest…

  • CVE-2024-33044HigDec 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while Configuring the SMR/S2CR register in Bypass mode.

  • CVE-2023-43535HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.

  • CVE-2023-33053HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Kernel while parsing metadata.

  • CVE-2022-40534HigSep 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to improper validation of array index in Audio.

  • CVE-2022-33275HigSep 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.

  • CVE-2022-40539HigMar 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive Android OS due to improper validation of array index.

  • CVE-2022-33274HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in android core due to improper validation of array index while returning feature ids after license authentication.

  • CVE-2022-25695HigDec 13, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice…

  • CVE-2022-22099HigSep 2, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto

  • CVE-2021-35126HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in DSP service due to improper validation of input parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30282HigJan 3, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible out of bound write in RAM partition table due to improper validation on number of partitions provided in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2022-49022HigOct 21, 2024
    risk 0.53cvss 8.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: wifi: mac8021: fix possible oob access in ieee80211_get_rate_duration Fix possible out-of-bound access in ieee80211_get_rate_duration routine as reported by the following UBSAN report: UBSAN:…

  • CVE-2023-2008HigApr 14, 2023
    risk 0.53cvss 8.2epss 0.01

    A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escalate privileges and…

  • CVE-2022-46152HigNov 29, 2022
    risk 0.53cvss 8.2epss 0.00

    OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper Validation of Array Index vulnerability. The function `cleanup_shm_refs()` is called by both `entry_invoke_command()` and…