CWE-129: CWE-129

191
Total CVEs
21
Critical
148
High
7.9
Avg CVSS

Yearly Trend

2026
7
2025
59
2024
69
2023
13
2022
25

Top Affected Vendors

1 Linux 84
2 Qualcomm 35
3 Debian 34
4 Cgal 23
5 Huawei 6
6 Tonybybell 3
7 Fedoraproject 3
8 Schneider Electric 3
9 Ffmpeg 2
10 Apache 2

All CWE-129 CVEs (191)

CVE-2023-28565
7.8

This vulnerability allows memory corruption in Qualcomm's WLAN Hardware Abstraction Layer (HAL) when processing command streams through WMI interfaces...

Sep 5, 2023
CVE-2023-28573
7.8

This vulnerability allows memory corruption in Qualcomm's WLAN Hardware Abstraction Layer (HAL) when parsing WMI command parameters. Attackers could p...

Sep 5, 2023
CVE-2023-28558
7.8

This vulnerability allows memory corruption in Qualcomm WLAN handlers when processing PhyID in Tx status handlers. It affects devices with Qualcomm ch...

Sep 5, 2023
CVE-2023-2008
7.8

This vulnerability in the Linux kernel's udmabuf driver allows local attackers to escalate privileges and execute arbitrary code with kernel permissio...

Apr 14, 2023
CVE-2021-35072
7.8

This vulnerability allows attackers to execute arbitrary code or cause denial of service on Qualcomm Snapdragon devices by sending specially crafted D...

Jun 14, 2022
CVE-2021-30311
7.8

This vulnerability allows heap overflow attacks due to improper index validation in Qualcomm Snapdragon chipsets before allocating and writing to heap...

Jan 13, 2022
CVE-2025-65562
7.5

CVE-2025-65562 is an unauthenticated denial-of-service vulnerability in free5GC UPF where specially crafted PFCP Session Deletion Requests with large ...

Dec 18, 2025
CVE-2025-48075
7.5

A denial-of-service vulnerability in Go's Fiber web framework allows attackers to crash applications by sending specially crafted requests with negati...

May 22, 2025
CVE-2024-36740
7.5

This vulnerability in OneFlow v0.9.1 allows attackers to cause Denial of Service (DoS) by providing a negative index that exceeds the valid range, pot...

Jun 6, 2024
CVE-2024-36743
7.5

This vulnerability in OneFlow v0.9.1 allows attackers to cause Denial of Service (DoS) by passing an empty array to the oneflow.dot function. The issu...

Jun 6, 2024
CVE-2024-34050
7.5

This vulnerability in rimedo-ts 0.1.1 allows attackers to cause a denial-of-service (DoS) by triggering a slice bounds out-of-range panic in the reade...

Apr 30, 2024
CVE-2024-23084
7.5

CVE-2024-23084 is a disputed vulnerability in Apfloat v1.10.1 where an ArrayIndexOutOfBoundsException occurs in the DoubleCRTMath::add method. If expl...

Apr 8, 2024
CVE-2022-35737
EPSS 51.9% 7.5

This SQLite vulnerability allows array-bounds overflow when processing extremely large string arguments (billions of bytes) through certain C API func...

Aug 3, 2022
CVE-2021-37057
7.5

This CVE describes an Improper Validation of Array Index vulnerability in Huawei smartphones running HarmonyOS. Attackers could exploit this to cause ...

Dec 7, 2021
CVE-2020-18430
7.5

CVE-2020-18430 is an array index error in tinyexr 0.9.5's DecodeEXRImage component that can cause denial of service through application crashes. This ...

Jul 26, 2021
CVE-2024-5680
7.1

A local privilege escalation vulnerability in the Foxboro.sys driver allows authenticated attackers to cause denial-of-service through improper array ...

Jul 11, 2024
CVE-2021-47449
7.1

A locking vulnerability in the Linux kernel's Intel ice network driver causes a potential deadlock during device removal when Tx timestamp tracking is...

May 22, 2024
CVE-2023-52640
7.1

This vulnerability is an out-of-bounds read in the NTFS3 filesystem driver in the Linux kernel, specifically in the ntfs_listxattr function. It allows...

Apr 3, 2024
CVE-2023-2570
7.0

This vulnerability in the Foxboro.sys driver allows local attackers to cause denial-of-service or potentially execute kernel code by sending specially...

Jun 14, 2023
CVE-2024-35164
6.8

This vulnerability in Apache Guacamole allows authenticated attackers with access to text-based connections (like SSH) to execute arbitrary code on th...

Jul 2, 2025
CVE-2024-33032
6.7

This CVE describes a memory corruption vulnerability in Qualcomm components where asynchronous modification of shared memory by user applications whil...

Nov 4, 2024
CVE-2026-0529
6.5

An improper array index validation vulnerability in Packetbeat's MongoDB protocol parser allows attackers to cause buffer overflows via specially craf...

Jan 14, 2026
CVE-2026-0528
6.5

This CVE describes two denial-of-service vulnerabilities in Metricbeat where specially crafted payloads sent to Graphite or Zookeeper metricsets, or m...

Jan 13, 2026
CVE-2025-62372
6.5

This vulnerability allows users to crash the vLLM inference engine by passing malformed multimodal embedding inputs with correct dimensionality but in...

Nov 21, 2025
CVE-2025-30077
6.2

This vulnerability in ONOS onos-lib-go allows an attacker to trigger an index out-of-range panic in the ASN.1 APER GetBitString function when a zero v...

Mar 16, 2025
CVE-2026-25518
5.9

This vulnerability in cert-manager allows attackers to cause denial-of-service by poisoning DNS caches during ACME DNS-01 challenge processing. Attack...

Feb 4, 2026
CVE-2023-52768
5.6

This is a memory corruption vulnerability in the Linux kernel's wilc1000 WiFi driver where improper memory allocation leads to a buffer overflow. Atta...

May 21, 2024
CVE-2025-39728
5.5

This CVE describes an array bounds vulnerability in the Linux kernel's Samsung clock management unit driver. When UBSAN (Undefined Behavior Sanitizer)...

Apr 18, 2025
CVE-2024-57996
5.5

A Linux kernel vulnerability in the Stochastic Fair Queueing (SFQ) network scheduler allows an array index out-of-bounds access when configured with a...

Feb 27, 2025
CVE-2024-26969
5.5

This CVE-2024-26969 is a buffer overflow vulnerability in the Linux kernel's Qualcomm GCC IPQ8074 clock driver. Missing termination in frequency table...

May 1, 2024
CVE-2024-26971
5.5

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's Qualcomm GCC IPQ5018 clock driver. Missing termination in frequency table...

May 1, 2024
CVE-2025-54610
5.4

This CVE describes an out-of-bounds access vulnerability in an audio codec module that could allow attackers to cause denial of service conditions. Th...

Aug 6, 2025
CVE-2024-53009
5.3

This CVE describes a memory corruption vulnerability in the mailbox component of Qualcomm automotive systems. Attackers could potentially execute arbi...

Jul 8, 2025
CVE-2025-54645
5.0

This CVE describes an out-of-bounds array access vulnerability in Huawei's location service module due to insufficient data verification. Successful e...

Aug 6, 2025
CVE-2024-47249
5.0

Apache NimBLE versions through 1.7.0 have an improper array index validation vulnerability in HCI event handling that could allow memory corruption an...

Nov 26, 2024
CVE-2025-65499
4.3

An array index error in OISM libcoap's TLS verification callback allows remote attackers to cause denial of service via a crafted DTLS handshake. This...

Nov 24, 2025
CVE-2024-41564
4.3

This vulnerability in EMI mod for Minecraft allows in-game item duplication through improper validation of slot indexes and stack counts. It affects a...

Aug 28, 2024
CVE-2025-54650
4.2

This vulnerability involves improper array index verification in an audio codec module, allowing attackers to potentially disrupt audio decoding funct...

Aug 6, 2025
CVE-2023-20601
N/A

This vulnerability allows a local attacker to exploit improper input validation in AMD's RAS TA Driver to access out-of-bounds memory. This could lead...

Feb 12, 2026
CVE-2026-25068
N/A

This CVE describes a heap-based buffer overflow vulnerability in alsa-lib's topology mixer control decoder. Attackers can exploit this by providing a ...

Jan 29, 2026
CVE-2025-66559
N/A

This vulnerability in Taiko Alethia rollup software allows corruption of the verified chain pointer when batch verification fails, potentially disrupt...

Dec 4, 2025

About CWE-129 (CWE-129)

Our database tracks 191 CVEs classified as CWE-129, with 21 rated critical and 148 rated high severity. The average CVSS score for CWE-129 vulnerabilities is 7.9.

External reference: View CWE-129 on MITRE CWE →

Monitor CWE-129 Vulnerabilities

Get alerted when new CWE-129 CVEs affect your infrastructure.

Start Monitoring Free