A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 a
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bou
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attacke
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_m
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
Memory corruption while using Strongbox due to missing bounds check.
The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow se
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression revers
Memory corruption when accessing resources in kernel driver.
In the Linux kernel, the following vulnerability has been resolved: net: rose: fix invalid array index in rose_kill_by_
In the Linux kernel, the following vulnerability has been resolved: clk: samsung: exynos-clkout: Assign .num before acc
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
In the Linux kernel, the following vulnerability has been resolved: x86/fred: Correct speculative safety in fred_extint
In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes b
In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes b
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: validate connector number in ucsi
In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: Set buffer sampling frequency
In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Fix missing SPDIFI1 index handling SP
In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_
In the Linux kernel, the following vulnerability has been resolved: mtd: intel-dg: Fix accessing regions before setting
In the Linux kernel, the following vulnerability has been resolved: wifi: b43: enforce bounds check on firmware key ind
In the Linux kernel, the following vulnerability has been resolved: wifi: b43legacy: enforce bounds check on firmware k
In the Linux kernel, the following vulnerability has been resolved: KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeade
The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper
NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A succ
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1298: add bounds check to pga_setti
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: CGX: add bounds check to cgx_speed_mb
In the Linux kernel, the following vulnerability has been resolved: Input: touchwin - reset the packet index on every c
In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - fix touch indexing for MMS134S and
In the Linux kernel, the following vulnerability has been resolved: Input: iforce - bound the device-reported force-fee
Frequently Asked Questions
What is CWE-129?
CWE-129 (CWE-129) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-129?
There are 105 CVE records associated with CWE-129 in our database. Of these, 5 are critical severity, 66 are high severity, and 27 are medium severity.
How can I protect against CWE-129 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-129 using AI-powered security agents.
Detect CWE-129 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-129 vulnerabilities across your infrastructure.
Get Started