CWE-1285: Improper Validation of Specified Index, Position, or Offset in Input
The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.
51 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-3357 — IBM Tivoli Monitoring code execution
- CVE-2025-3755 — Information Disclosure and Denial-of-Service(DoS) Vulnerability in MELSEC iQ-F Series CPU module
- CVE-2024-36342 — Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in
- CVE-2025-7849 — Memory Corruption Issue in NI LabVIEW due to improper error handling
- CVE-2025-7848 — Missing input check in lvpict.cpp used in NI LabVIEW
- CVE-2025-57778 — Out Of Bounds Write to invalid source address when parsing a DSB file with Digilent DASYLab
- CVE-2025-57777 — Out Of Bounds Write in displ2.dll when parsing a DSB file with Digilent DASYLab
- CVE-2025-57776 — Out Of Bounds Write to invalid address when parsing a DSB file with Digilent DASYLab
- CVE-2025-57775 — Heap-based Buffer Overflow when parsing a DSB file with Digilent DASYLab
- CVE-2025-57774 — Out Of Bounds Write of invalid data when parsing a DSB file with Digilent DASYLab
- CVE-2024-10496 — Out of bounds read in BuildFontMap in fontmgr.cpp in NI LabVIEW
- CVE-2024-10495 — Out of bounds read when loading the font table in fontmgr.cpp in NI LabVIEW
- CVE-2024-10494 — Out of bounds read in HeapObjMapImpl.cpp in NI LabVIEW
- CVE-2025-2634 — Out of Bounds Read Vulnerability in NI LabVIEW when building font map
- CVE-2025-2633 — Out of Bounds Read Vulnerability in NI LabVIEW when loading fonts
- CVE-2025-20796 — In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation
- CVE-2024-23612 — Improper Error Handling Issue in LabVIEW
- CVE-2024-23609 — Improper Error Handling Issue in LabVIEW
- CVE-2026-12681 — Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig
- CVE-2026-53530 — ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
Recently published
- CVE-2026-31912 — OOBR in libpcap before 1.10.7
- CVE-2026-53530 — ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
- CVE-2026-14479 — Denial of Service in Autodesk Installer IPC Channel
- CVE-2026-18485 — Local Privilege Escalation in NI-PAL
- CVE-2026-12681 — Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig
- CVE-2026-8036 — Local privilege escalation in NI-PAL
- CVE-2026-45352 — cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding
- CVE-2026-9100 — Heap memory out of bounds read and crash in C Driver legacy GridFS file reader
- CVE-2026-33557 — Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
- CVE-2018-25232 — Softros LAN Messenger 9.2 Denial of Service via Log Files Location
- CVE-2019-25625 — Blob Studio 2.17 Denial of Service via Malformed Input
- CVE-2019-25622 — Paint Studio 2.17 Denial of Service via Malformed Input
- CVE-2019-25593 — jetCast Server 2.0 Denial of Service via Log Directory
- CVE-2025-2399 — Denial of Service (DoS) Vulnerability in Mitsubishi Electric CNC Series
- CVE-2026-20440 — In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
- CVE-2026-20413 — In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
- CVE-2025-20796 — In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation
- CVE-2025-48511 — Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potenti
- CVE-2025-48502 — Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting
- CVE-2025-55086 — In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there