Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-129

MITRE ↗

CWE-129

62
CRITICAL
418
HIGH
118
MEDIUM
7
LOW
612 CVEs · Page 7/13
5.5
CVE-2024-32673

Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segme

5.5
CVE-2024-49970

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Implement bounds check for stream

5.4
CVE-2024-29231

Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station

5.3
CVE-2024-21493

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when

5.3
CVE-2024-26755

In the Linux kernel, the following vulnerability has been resolved: md: Don't suspend the array for interrupted reshape

5.1
CVE-2024-51517

Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerabilit

5.0
CVE-2024-47249

Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from control

4.4
CVE-2021-47547

In the Linux kernel, the following vulnerability has been resolved: net: tulip: de4x5: fix the problem that the array '

4.3
CVE-2024-34047

O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler.

4.3
CVE-2024-42698

Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset

4.3
CVE-2024-41564

EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in I

4.3
CVE-2024-41565

JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in In

2.3
CVE-2023-31307

Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-o

9.8
CVE-2023-0755

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash t

9.8
CVE-2022-33256

Memory corruption due to improper validation of array index in Multi-mode call processor.

9.8
CVE-2023-26066

Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

9.8
CVE-2023-28004

A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request coul

8.8
CVE-2022-48503 KEV

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS

8.6
CVE-2023-20080

A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could all

8.6
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 throu

8.4
CVE-2022-33274

Memory corruption in android core due to improper validation of array index while returning feature ids after license au

8.4
CVE-2022-40539

Memory corruption in Automotive Android OS due to improper validation of array index.

8.4
CVE-2022-33275

Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.

8.4
CVE-2022-40534

Memory corruption due to improper validation of array index in Audio.

8.4
CVE-2023-33053

Memory corruption in Kernel while parsing metadata.

8.2
CVE-2023-2008

A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack

7.8
CVE-2023-0950

Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice all

7.8
CVE-2023-28548

Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.

7.8
CVE-2023-28557

Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.

7.8
CVE-2023-28558

Memory corruption in WLAN handler while processing PhyID in Tx status handler.

7.8
CVE-2023-28565

Memory corruption in WLAN HAL while handling command streams through WMI interfaces.

7.8
CVE-2023-28567

Memory corruption in WLAN HAL while handling command through WMI interfaces.

7.8
CVE-2023-28573

Memory corruption in WLAN HAL while parsing WMI command parameters.

7.8
CVE-2023-24850

Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.

7.8
CVE-2023-35126

An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles

7.5
CVE-2023-22401

An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemon (aftmand) of Junip

7.5
CVE-2023-22408

An Improper Validation of Array Index vulnerability in the SIP ALG of Juniper Networks Junos OS on SRX 5000 Series allow

7.3
CVE-2022-40537

Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response.

7.0
CVE-2023-2570

A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and pote

6.8
CVE-2022-33289

Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

6.8
CVE-2022-33302

Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than

6.7
CVE-2023-20633

In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2022-33281

Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending

6.7
CVE-2023-21650

Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.

6.7
CVE-2023-21636

Memory Corruption due to improper validation of array index in Linux while updating adn record.

6.5
CVE-2022-38072

An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master

5.9
CVE-2023-29458

Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too

5.5
CVE-2022-47342

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermod

5.5
CVE-2022-47343

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermod

5.5
CVE-2022-47344

In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermod

Frequently Asked Questions

What is CWE-129?

CWE-129 (CWE-129) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-129?

There are 751 CVE records associated with CWE-129 in our database. Of these, 62 are critical severity, 418 are high severity, and 118 are medium severity.

How can I protect against CWE-129 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-129 using AI-powered security agents.

Detect CWE-129 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-129 vulnerabilities across your infrastructure.

Get Started