The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.
Volume of CVEs assigned to CWE-1285 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2006HIGH Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to ex | Feb 12, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-44004HIGH vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because B | May 13, 2026 | 8.6 | 35 | NO | NO |
CVE-2026-33557CRITICAL A possible security vulnerability has been identified in Apache Kafka.
By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.se | Apr 20, 2026 | 9.1 | 35 | NO | NO |
CVE-2025-67268CRITICAL gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 | Jan 2, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-12681HIGH Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes b | Jun 24, 2026 | 8.9 | 33 | NO | NO |
CVE-2026-8036HIGH Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects | Jun 2, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-43868HIGH Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, w | May 5, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-45352HIGH cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocati | May 29, 2026 | 7.5 | 31 | NO | NO |
CVE-2025-55086CRITICAL In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked index extracting the server DUID from the s | Oct 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-32286HIGH The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing | Mar 26, 2026 | 7.5 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.