Vulnerabilities > Improper Validation of Array Index

DATE CVE VULNERABILITY TITLE RISK
2018-02-23 CVE-2017-15861 Improper Validation of Array Index vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function wma_roam_synch_event_handler, vdev_id is received from firmware and used to access an array without validation.
local
low complexity
google CWE-129
7.2
2017-12-09 CVE-2017-16410 Improper Validation of Array Index vulnerability in Adobe products
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions.
network
adobe CWE-129
critical
9.3
2017-12-09 CVE-2017-16391 Improper Validation of Array Index vulnerability in Adobe products
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions.
network
adobe CWE-129
critical
9.3
2017-11-22 CVE-2017-8172 Improper Validation of Array Index vulnerability in Huawei P10 Firmware and P10 Plus Firmware
Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions has a denial of service (DoS) vulnerability.
network
huawei CWE-129
7.1
2017-11-20 CVE-2017-16899 Improper Validation of Array Index vulnerability in multiple products
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.
5.8
2017-11-16 CVE-2017-0836 Improper Validation of Array Index vulnerability in Google Android
A remote code execution vulnerability in the Android media framework (libhevc).
network
google CWE-129
critical
9.3
2017-09-21 CVE-2017-8251 Improper Validation of Array Index vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msm_isp_check_stream_cfg_cmd & msm_isp_stats_update_cgc_override, 'stream_cfg_cmd->num_streams' is not checked, and could overflow the array stream_cfg_cmd->stream_handle.
network
google CWE-129
6.8
2017-09-06 CVE-2015-8316 Improper Validation of Array Index vulnerability in Lightdm Project Lightdm
Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.
4.3
2017-08-24 CVE-2014-4616 Improper Validation of Array Index vulnerability in multiple products
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
4.3
2017-08-24 CVE-2017-0805 Improper Validation of Array Index vulnerability in Google Android
A elevation of privilege vulnerability in the Android media framework (libstagefright).
network
google CWE-129
critical
9.3