The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.
Volume of CVEs assigned to CWE-118 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50367HIGH Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | 7.8 | 33 | NO | NO |
CVE-2015-2004CRITICAL The GraceNote GNSDK SDK before SVN Changeset 1.1.7 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improper | Mar 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2016-10495CRITICAL In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, made changes to map the scan type value to an index value that is in range. | Apr 18, 2018 | 9.8 | 28 | NO | NO |
CVE-2022-38072HIGH An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can | Apr 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2015-2003CRITICAL The PJSIP PJSUA2 SDK before SVN Changeset 51322 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly | Mar 29, 2018 | 9.8 | 27 | NO | NO |
CVE-2020-3235HIGH A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authentic | Jun 3, 2020 | 7.7 | 26 | NO | NO |
CVE-2015-2000CRITICAL The Jumio SDK before 1.5.0 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-co | Mar 29, 2018 | 9.8 | 26 | NO | NO |
CVE-2015-9142CRITICAL In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9645, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435 | Apr 18, 2018 | 9.8 | 24 | NO | NO |
CVE-2018-7530HIGH Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prio | Apr 17, 2018 | 7.8 | 24 | NO | NO |
CVE-2015-2002CRITICAL The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly pass | Mar 29, 2018 | 9.8 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.