Vulnerabilities > Improper Validation of Array Index

DATE CVE VULNERABILITY TITLE RISK
2017-12-09 CVE-2017-16391 Improper Validation of Array Index vulnerability in Adobe products
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions.
network
low complexity
adobe CWE-129
8.8
2017-11-22 CVE-2017-8172 Improper Validation of Array Index vulnerability in Huawei P10 Firmware and P10 Plus Firmware
Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions has a denial of service (DoS) vulnerability.
local
low complexity
huawei CWE-129
5.5
2017-11-20 CVE-2017-16899 Improper Validation of Array Index vulnerability in multiple products
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.
local
low complexity
xfig-project debian CWE-129
7.1
2017-11-16 CVE-2017-0836 Improper Validation of Array Index vulnerability in Google Android
A remote code execution vulnerability in the Android media framework (libhevc).
local
low complexity
google CWE-129
7.8
2017-09-21 CVE-2017-8251 Improper Validation of Array Index vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msm_isp_check_stream_cfg_cmd & msm_isp_stats_update_cgc_override, 'stream_cfg_cmd->num_streams' is not checked, and could overflow the array stream_cfg_cmd->stream_handle.
local
low complexity
google CWE-129
7.8
2017-09-06 CVE-2015-8316 Improper Validation of Array Index vulnerability in Lightdm Project Lightdm
Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.
network
high complexity
lightdm-project CWE-129
5.9
2017-08-24 CVE-2014-4616 Improper Validation of Array Index vulnerability in multiple products
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
5.9
2017-08-24 CVE-2017-0805 Improper Validation of Array Index vulnerability in Google Android
A elevation of privilege vulnerability in the Android media framework (libstagefright).
local
low complexity
google CWE-129
7.8
2017-08-19 CVE-2017-10663 Improper Validation of Array Index vulnerability in Linux Kernel
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
local
low complexity
linux CWE-129
7.8
2017-08-18 CVE-2016-10386 Improper Validation of Array Index vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.
network
low complexity
google CWE-129
critical
9.8