Vulnerabilities > Improper Validation of Array Index

DATE CVE VULNERABILITY TITLE RISK
2017-08-24 CVE-2017-0805 Improper Validation of Array Index vulnerability in Google Android
A elevation of privilege vulnerability in the Android media framework (libstagefright).
network
google CWE-129
critical
9.3
2017-08-19 CVE-2017-10663 Improper Validation of Array Index vulnerability in Linux Kernel
The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.
local
low complexity
linux CWE-129
7.8
2017-08-18 CVE-2016-10386 Improper Validation of Array Index vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.
network
low complexity
google CWE-129
critical
10.0
2017-08-09 CVE-2017-0737 Improper Validation of Array Index vulnerability in Google Android
A elevation of privilege vulnerability in the Android media framework (libstagefright).
network
google CWE-129
6.8
2017-08-09 CVE-2017-0716 Improper Validation of Array Index vulnerability in Google Android
A remote code execution vulnerability in the Android media framework (libmpeg2).
network
google CWE-129
critical
9.3
2017-07-02 CVE-2017-8797 Improper Validation of Array Index vulnerability in Linux Kernel
The NFSv4 server in the Linux kernel before 4.11.3 does not properly validate the layout type when processing the NFSv4 pNFS GETDEVICEINFO or LAYOUTGET operand in a UDP packet from a remote attacker.
network
low complexity
linux CWE-129
7.5
2017-06-06 CVE-2014-9948 Improper Validation of Array Index vulnerability in Google Android
In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Validation of Array Index vulnerability could potentially exist.
network
google CWE-129
critical
9.3
2017-05-09 CVE-2017-0347 Improper Validation of Array Index vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array, which may lead to denial of service or potential escalation of privileges.
local
low complexity
nvidia microsoft CWE-129
7.2
2017-05-09 CVE-2017-0345 Improper Validation of Array Index vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input used as an array size is not correctly validated allows out of bound access in kernel memory and may lead to denial of service or potential escalation of privileges
local
low complexity
nvidia microsoft CWE-129
7.2
2017-04-04 CVE-2017-7228 Improper Validation of Array Index vulnerability in XEN
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x.
local
low complexity
xen CWE-129
7.2