CWE-129— Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.— MITRE CWE catalog
672 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-129page 11 of 14
- CVE-2024-5680HIGHCVSS 7.1EG 7.12024-07-11
CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
- CVE-2024-38542HIGHCVSS 7.1EG 7.12024-06-19
In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: boundary check before installing cq callbacks Add a boundary check inside mana_ib_install_cq_cb to prevent index overflow.
- CVE-2021-47449HIGHCVSS 7.1EG 7.12024-05-22
In the Linux kernel, the following vulnerability has been resolved: ice: fix locking for Tx timestamp tracking flush Commit 4dd0d5c33c3e ("ice: add lock around Tx timestamp tracker flush") added a lock around the Tx timestamp tracker flo…
- CVE-2023-52640HIGHCVSS 7.1EG 7.12024-04-03
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix oob in ntfs_listxattr The length of name cannot exceed the space occupied by ea.
- CVE-2017-18309HIGHCVSS 7.1EG 7.12018-10-26
A micro-core of QMP transportation may cause a macro-core to read from or write to arbitrary memory in Snapdragon Mobile in version SD 845, SD 850.
- CVE-2017-16899HIGHCVSS 7.1EG 7.12017-11-20
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c,…
- CVE-2014-6317HIGHCVSS v2 7.1EG 7.12014-11-11
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT …
- CVE-2026-52969HIGHCVSS 7.0EG 7.02026-06-24
In the Linux kernel, the following vulnerability has been resolved: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() kvm_reset_dirty_gfn() guards the gfn range with if (!memslot || (offset + __fls(mask)) >= memslot->npages) return…
- CVE-2025-71203HIGHCVSS 7.0EG 7.02026-02-14
In the Linux kernel, the following vulnerability has been resolved: riscv: Sanitize syscall table indexing under speculation The syscall number is a user-controlled value used to index into the syscall table. Use array_index_nospec() to …
- CVE-2024-2214HIGHCVSS 7.0EG 7.02024-03-26
In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected file was ports/xtensa/xcc/src/tx_clib_lock.c
- CVE-2023-2570HIGHCVSS 7.0EG 7.02023-06-14
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable i…
- CVE-2026-93321MEDIUMCVSS 6.9EG 6.92026-10-05
A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
- CVE-2026-93322MEDIUMCVSS 6.9EG 6.92026-10-05
A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
- CVE-2007-5756MEDIUMCVSS v2 6.9EG 6.92007-11-14
Multiple array index errors in the bpf_filter_init function in NPF.SYS in WinPcap before 4.0.2, when run in monitor mode (aka Table Management Extensions or TME), and as used in Wireshark and possibly other products, allow local users to g…
- CVE-2023-31309MEDIUMCVSS 6.8EG 6.82026-05-15
Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to DRAM potentially resulting in a loss of confidentiality and/or availab…
- CVE-2024-35164MEDIUMCVSS 6.8EG 6.82025-07-02
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequ…
- CVE-2023-51455MEDIUMCVSS 6.8EG 6.82024-04-02
A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to corrupt a controlled memory location due to a missing input validation in the on_rec…
- CVE-2022-33289MEDIUMCVSS 6.8EG 6.82023-04-13
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
- CVE-2020-11308MEDIUMCVSS 6.8EG 6.82021-03-17
Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snap…
- CVE-2010-2806MEDIUMCVSS v2 6.8EG 6.82010-08-19
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certai…
- CVE-2026-47533MEDIUMCVSS 6.7EG 6.72026-09-30
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code executi…
- CVE-2026-47525MEDIUMCVSS 6.7EG 6.72026-09-30
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code executi…
- CVE-2025-61915MEDIUMCVSS 6.7EG 6.72025-11-29
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cu…
- CVE-2024-33032MEDIUMCVSS 6.7EG 6.72024-11-04
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
- CVE-2023-21636MEDIUMCVSS 6.7EG 6.72023-09-05
Memory Corruption due to improper validation of array index in Linux while updating adn record.
- CVE-2023-21650MEDIUMCVSS 6.7EG 6.72023-08-08
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
- CVE-2022-33281MEDIUMCVSS 6.7EG 6.72023-05-02
Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending any frames.
- CVE-2023-20633MEDIUMCVSS 6.7EG 6.72023-03-07
In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762850…
- CVE-2021-35121MEDIUMCVSS 6.7EG 6.72022-06-14
An array index is improperly used to lock and unlock a mutex which can lead to a Use After Free condition In the Synx driver in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-30325MEDIUMCVSS 6.7EG 6.72022-02-11
Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music…
- CVE-2025-54644MEDIUMCVSS 6.6EG 6.62025-08-06
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-54643MEDIUMCVSS 6.6EG 6.62025-08-06
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-52819MEDIUMCVSS 6.6EG 6.62024-05-21
In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga For pptable structs that use flexible array sizes, use flexible arrays.
- CVE-2026-107225MEDIUMCVSS 6.5EG 6.52026-10-07
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.0 to 2.11.0, GetStyle's fill, border, and font extraction predicates check only upper bounds for attacker-controlled style-table indices. File…
- CVE-2026-107222MEDIUMCVSS 6.5EG 6.52026-10-07
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.0 to 2.11.0, conditional-format extraction indexes required child slices or dereferences an optional colorScale child without validating malfo…
- CVE-2026-107220MEDIUMCVSS 6.5EG 6.52026-10-07
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.1 to 2.11.0, mergeCellsParser leaves the cached rectangle empty for an empty mergeCell ref and then passes that empty slice to cellInRange wit…
- CVE-2026-100654MEDIUMCVSS 6.5EG 6.52026-09-26
vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints but validates only that the values are integers, not that each token id is within the model voc…
- CVE-2023-54396MEDIUMCVSS 6.5EG 6.52026-09-09
PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash…
- CVE-2026-79775MEDIUMCVSS 6.5EG 6.52026-08-25
rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to valid…
- CVE-2026-53792MEDIUMCVSS 6.5EG 6.52026-08-13
rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block…
- CVE-2026-63308MEDIUMCVSS 6.5EG 6.52026-07-17
Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte sl…
- CVE-2026-32682MEDIUMCVSS 6.5EG 6.52026-06-17
When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRo…
- CVE-2026-44222MEDIUMCVSS 6.5EG 6.52026-05-12
vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Token Injection vulnerability in vLLM’s multimodal processing. Unauthenticated, text-only prompts that spell special toke…
- CVE-2026-40251MEDIUMCVSS 6.5EG 6.52026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon…
- CVE-2026-34942MEDIUMCVSS 6.5EG 6.52026-04-09
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings into the Component Model's utf16 or latin1+utf16 encodings improperly verified the alignment of reallocate…
- CVE-2026-33022MEDIUMCVSS 6.5EG 6.52026-03-20
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0, 1.1.0 through 1.3.2, 1.4.0 through 1.6.0, 1.7.0 through 1.9.0, 1.10.0, and 1.10.1 have a denial-of-service vulnerabil…
- CVE-2026-32937MEDIUMCVSS 6.5EG 6.52026-03-20
free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerability in the CHF `nchf-convergedcharging` service. A valid authenticated request to PUT `/nchf-convergedcharging/v3/rec…
- CVE-2026-0529MEDIUMCVSS 6.5EG 6.52026-01-14
Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Overflow Buffers (CAPEC-100) through specially crafted network traffic. This requires an attacker to send a malformed pay…
- CVE-2025-62372MEDIUMCVSS 6.5EG 6.52025-11-21
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect…
- CVE-2023-6298MEDIUMCVSS 6.5EG 6.52023-11-26
A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to improper validation of array index. The attack can be initiated…
Map vulnerabilities like CWE-129 to your infrastructure
EchelonGraph correlates every CVE — across CWE-129 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →