CWE-129— Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.— MITRE CWE catalog
605 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-129page 7 of 13
- CVE-2022-49186HIGHCVSS 7.8EG 7.82025-02-26
In the Linux kernel, the following vulnerability has been resolved: clk: visconti: prevent array overflow in visconti_clk_register_gates() This code was using -1 to represent that there was no reset function. Unfortunately, the -1 was st…
- CVE-2022-49471HIGHCVSS 7.8EG 7.82025-02-26
In the Linux kernel, the following vulnerability has been resolved: rtw89: cfo: check mac_id to avoid out-of-bounds Somehow, hardware reports incorrect mac_id and pollute memory. Check index before we access the array. UBSAN: array-in…
- CVE-2022-49478HIGHCVSS 7.8EG 7.82025-02-26
In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix array-index-out-of-bounds in pvr2_i2c_core_init Syzbot reported that -1 is used as array index. The problem was in missing validation check. hdw->un…
- CVE-2022-49548HIGHCVSS 7.8EG 7.82025-02-26
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential array overflow in bpf_trampoline_get_progs() The cnt value in the 'cnt >= BPF_MAX_TRAMP_PROGS' check does not include BPF_TRAMP_MODIFY_RETURN bpf prog…
- CVE-2022-49720HIGHCVSS 7.8EG 7.82025-02-26
In the Linux kernel, the following vulnerability has been resolved: block: Fix handling of offline queues in blk_mq_alloc_request_hctx() This patch prevents that test nvme/004 triggers the following: UBSAN: array-index-out-of-bounds in …
- CVE-2022-50066HIGHCVSS 7.8EG 7.82025-06-18
In the Linux kernel, the following vulnerability has been resolved: net: atlantic: fix aq_vec index out of range error The final update statement of the for loop exceeds the array range, the dereference of self->aq_vec[i] is not checked …
- CVE-2022-50315HIGHCVSS 7.8EG 7.82025-09-15
In the Linux kernel, the following vulnerability has been resolved: ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS UBSAN complains about array-index-out-of-bounds: [ 1.980703] kernel: UBSAN: array-index-out-of-bounds in /build/lin…
- CVE-2023-0755CRITICALCVSS 9.8EG 9.82023-02-23
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
- CVE-2023-0950CRITICALCVSS 7.8EG 9.82023-05-25
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected v…
- CVE-2023-2008HIGHCVSS 7.8EG 7.82023-04-14
A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of …
- CVE-2023-20080HIGHCVSS 8.6EG 8.62023-03-23
A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to ins…
- CVE-2023-20601MEDIUMCVSS 4.6EG 4.62026-02-12
Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition.
- CVE-2023-20633MEDIUMCVSS 6.7EG 6.72023-03-07
In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762850…
- CVE-2023-21636MEDIUMCVSS 6.7EG 6.72023-09-05
Memory Corruption due to improper validation of array index in Linux while updating adn record.
- CVE-2023-21650MEDIUMCVSS 6.7EG 6.72023-08-08
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
- CVE-2023-22401HIGHCVSS 7.5EG 7.52023-01-13
An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemon (aftmand) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Servic…
- CVE-2023-22408HIGHCVSS 7.5EG 7.52023-01-13
An Improper Validation of Array Index vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX 5000 Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). When an attacker sends an SIP packets w…
- CVE-2023-24850HIGHCVSS 7.8EG 7.82023-10-03
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
- CVE-2023-2570HIGHCVSS 7.0EG 7.02023-06-14
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable i…
- CVE-2023-26066CRITICALCVSS 9.8EG 9.82023-04-10
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
- CVE-2023-27349HIGHCVSS 8.0EG 8.02024-05-03
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interac…
- CVE-2023-28004CRITICALCVSS 9.8EG 9.82023-04-18
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial of service or remote code execution.
- CVE-2023-28548HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
- CVE-2023-28557HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.
- CVE-2023-28558HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN handler while processing PhyID in Tx status handler.
- CVE-2023-28565HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
- CVE-2023-28567HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while handling command through WMI interfaces.
- CVE-2023-28573HIGHCVSS 7.8EG 7.82023-09-05
Memory corruption in WLAN HAL while parsing WMI command parameters.
- CVE-2023-29458MEDIUMCVSS 5.9EG 5.92023-07-13
Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solut…
- CVE-2023-31194MEDIUMCVSS 5.3EG 5.32023-07-05
An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption. A victim would need to open a malicious file to trigger th…
- CVE-2023-31306LOWCVSS 3.3EG 3.32025-09-06
Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management (DPM) functions resulting in an out of bounds read and loss of availability.
- CVE-2023-31307LOWCVSS 2.3EG 2.32024-08-13
Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.
- CVE-2023-31309MEDIUMCVSS 6.8EG 6.82026-05-15
Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to DRAM potentially resulting in a loss of confidentiality and/or availab…
- CVE-2023-33053HIGHCVSS 8.4EG 8.42023-12-05
Memory corruption in Kernel while parsing metadata.
- CVE-2023-33111MEDIUMCVSS 5.5EG 5.52024-04-01
Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command.
- CVE-2023-35126HIGHCVSS 7.8EG 7.82023-10-19
An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles" streams of Ichitaro 2023 1.0.1.59372 when processing types 0x0000-0x0009 of a style record with the type 0x2008. A sp…
- CVE-2023-35994HIGHCVSS 7.8EG 7.82024-01-08
Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious…
- CVE-2023-35995HIGHCVSS 7.8EG 7.82024-01-08
Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious…
- CVE-2023-35996HIGHCVSS 7.8EG 7.82024-01-08
Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious…
- CVE-2023-35997HIGHCVSS 7.8EG 7.82024-01-08
Multiple improper array index validation vulnerabilities exist in the fstReaderIterBlocks2 tdelta functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious…
- CVE-2023-36307MEDIUMCVSS 5.5EG 5.52023-09-05
ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which this panic could have…
- CVE-2023-36308MEDIUMCVSS 5.5EG 5.52023-09-05
disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use …
- CVE-2023-39234HIGHCVSS 7.8EG 7.82024-01-08
Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file …
- CVE-2023-39235HIGHCVSS 7.8EG 7.82024-01-08
Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file …
- CVE-2023-40477HIGHCVSS 7.8EG 7.82024-05-03
RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is requ…
- CVE-2023-43535HIGHCVSS 8.4EG 8.42024-02-06
Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.
- CVE-2023-46724HIGHCVSS 7.5EG 7.52023-11-01
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Ce…
- CVE-2023-51455MEDIUMCVSS 6.8EG 6.82024-04-02
A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to corrupt a controlled memory location due to a missing input validation in the on_rec…
- CVE-2023-52451HIGHCVSS 7.8EG 7.82024-02-22
In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/memhp: Fix access beyond end of drmem array dlpar_memory_remove_by_index() may access beyond the bounds of the drmem lmb array when the LMB lookup fails …
- CVE-2023-52594HIGHCVSS 7.8EG 7.82024-03-06
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus() Fix an array-index-out-of-bounds read in ath9k_htc_txstatus(). The bug occurs when txs-…
Map vulnerabilities like CWE-129 to your infrastructure
EchelonGraph correlates every CVE — across CWE-129 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →