Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: 8192cu: fix tid out of range in rtl9
free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of fr
Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 th
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can s
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.
MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always
libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences
DVP80ES300T with Improper Validation of Array Index Vulnerability
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArra
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a
NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H
In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option lists
ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434
In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6075: add bounds check to veml6075_
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bounds c
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica
In the Linux kernel, the following vulnerability has been resolved: riscv: Sanitize syscall table indexing under specul
Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service thr
Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Over
free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerab
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0
Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with i
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Toke
When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or
rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a ma
rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the a
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service
Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected vers
A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper t
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0
For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards call
Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template help
Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause a denial of service
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an impro
Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to befor
go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder f
Frequently Asked Questions
What is CWE-129?
CWE-129 (CWE-129) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-129?
There are 105 CVE records associated with CWE-129 in our database. Of these, 5 are critical severity, 66 are high severity, and 27 are medium severity.
How can I protect against CWE-129 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-129 using AI-powered security agents.
Detect CWE-129 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-129 vulnerabilities across your infrastructure.
Get Started