Vulnerabilities > Incorrect Access of Indexable Resource ('Range Error')

DATE CVE VULNERABILITY TITLE RISK
2019-01-11 CVE-2019-6130 Range Error vulnerability in Artifex Mupdf 1.14.0
Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool.
local
low complexity
artifex CWE-118
5.5
2018-04-18 CVE-2016-10495 Range Error vulnerability in Qualcomm Mdm9635M Firmware
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, made changes to map the scan type value to an index value that is in range.
network
low complexity
qualcomm CWE-118
critical
10.0
2018-04-18 CVE-2015-9142 Range Error vulnerability in Qualcomm products
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9645, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SDM630, SDM636, SDM660, and Snapdragon_High_Med_2016, bounds check is missing for vtable index in DAL-TO-QDI conversion framework.
network
low complexity
qualcomm CWE-118
critical
10.0
2018-04-17 CVE-2018-7530 Range Error vulnerability in Omron products
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may allow the pointer to call an incorrect object resulting in an access of resource using incompatible type condition.
local
low complexity
omron CWE-118
4.6
2018-03-29 CVE-2015-2004 Range Error vulnerability in Gracenote Gnsdk
The GraceNote GNSDK SDK before SVN Changeset 1.1.7 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
network
low complexity
gracenote CWE-118
7.5
2018-03-29 CVE-2015-2003 Range Error vulnerability in Pjsip Pjsua2 SDK
The PJSIP PJSUA2 SDK before SVN Changeset 51322 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
network
low complexity
pjsip CWE-118
7.5
2018-03-29 CVE-2015-2002 Range Error vulnerability in Esri Arcgisruntime SDK
The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
network
low complexity
esri CWE-118
7.5
2018-03-29 CVE-2015-2001 Range Error vulnerability in Metaio SDK
The MetaIO SDK before 6.0.2.1 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
network
low complexity
metaio CWE-118
7.5
2018-03-29 CVE-2015-2000 Range Error vulnerability in Jumio SDK
The Jumio SDK before 1.5.0 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
network
low complexity
jumio CWE-118
7.5
2017-12-22 CVE-2017-10872 H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.
network
low complexity
CWE-118
4.0