Skip to main content

CWE archive

CWE-129 CVEs

Programmatic archive

601 CVEs tagged with CWE-12957 Critical, 404 High, 133 Medium, 7 Low, 0 Unrated.

CVE-2024-38562

Published Jun 19, 2024

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: Avoid address calculations via out of bounds array indexing Before request->channels[] can be…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38556

Published Jun 19, 2024

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Add a timeout to acquire the command queue semaphore Prevent forced completion handling on an entry…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38552

Published Jun 19, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential index out of bounds in color transformation function Fixes index out of bounds…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38542

Published Jun 19, 2024

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: boundary check before installing cq callbacks Add a boundary check inside mana_ib_install_cq_cb…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36740

Published Jun 6, 2024

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of size.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36743

Published Jun 6, 2024

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36921

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: guard against invalid STA ID on removal Guard against invalid station IDs in iwl_mvm_mld_…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36015

Published May 29, 2024

In the Linux kernel, the following vulnerability has been resolved: ppdev: Add an error check in register_device In register_device, the return value of ida_simple_get is unchec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22181

Published May 28, 2024

An out-of-bounds write vulnerability exists in the readNODE functionality of libigl v2.5.0. A specially crafted .node file can lead to an out-of-bounds write. An attacker can prov…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47548

Published May 24, 2024

In the Linux kernel, the following vulnerability has been resolved: ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port() The if s…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-47547

Published May 24, 2024

In the Linux kernel, the following vulnerability has been resolved: net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound In line 5001, if all id in…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47449

Published May 22, 2024

In the Linux kernel, the following vulnerability has been resolved: ice: fix locking for Tx timestamp tracking flush Commit 4dd0d5c33c3e ("ice: add lock around Tx timestamp trac…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52835

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: perf/core: Bail out early if the request AUX area is out of bound When perf-record with a large AUX area, e.g…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52819

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga For pptable structs that use flexible arra…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52818

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix UBSAN array-index-out-of-bounds for SMU7 For pptable structs that use flexible array sizes, use…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52812

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/amd: check num of link levels when update pcie param In SR-IOV environment, the value of pcie_table->num_…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52807

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix out-of-bounds access may occur when coalesce info is read via debugfs The hns3 driver define a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52805

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in diAlloc Currently there is not check against the agno of the iag while…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52804

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: fs/jfs: Add validity check for db_maxag and db_agpref Both db_maxag and db_agpref are used as the index of th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52799

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in dbFindLeaf Currently while searching for dmtree_t for sufficient free b…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52768

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: use vmm_table as array in wilc struct Enabling KASAN and running some iperf tests raises some…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48702

Published May 3, 2024

In the Linux kernel, the following vulnerability has been resolved: ALSA: emu10k1: Fix out of bounds access in snd_emu10k1_pcm_channel_alloc() The voice allocator sometimes begi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40477

Published May 3, 2024

RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec…

CVSS 7.8 · High
evidence mentions
11
Buzz score
40.9
Vendor/product tagsBeta · best-effort

CVE-2023-27349

Published May 3, 2024

BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code vi…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 226-250 of 601 CVEsPage 10 of 25