CWE-120 未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出) 类弱点 1823 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-120 即经典缓冲区溢出,属于内存安全漏洞。当程序将输入数据复制到输出缓冲区时,若未验证输入大小是否超出目标容量,会导致内存越界写入。攻击者利用此缺陷可覆盖相邻内存数据,进而执行恶意代码或导致系统崩溃。开发者应严格校验输入长度,使用安全的边界检查函数,并确保目标缓冲区足够大,从而从根本上杜绝此类风险。
char last_name[20]; printf ("Enter your last name: "); scanf ("%s", last_name);void manipulate_string(char * string){ char buf[24]; strcpy(buf, string); ... }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2020-37215 | Top Password MSN Password Recovery 安全漏洞 — MSN Password Recovery | 7.5 | High | 2026-02-11 |
| CVE-2020-37213 | DigitalVolcano TextCrawler Pro 安全漏洞 — TextCrawler Pro | 7.5 | High | 2026-02-11 |
| CVE-2020-37212 | Nsasoft SpotMSN 安全漏洞 — Nsauditor SpotMSN | 7.5 | High | 2026-02-11 |
| CVE-2020-37211 | Nsasoft SpotIM 安全漏洞 — Nsauditor SpotIM | 7.5 | High | 2026-02-11 |
| CVE-2020-37210 | Nsasoft SpotIE 安全漏洞 — Nsauditor SpotIE | 7.5 | High | 2026-02-11 |
| CVE-2020-37209 | Nsasoft SpotFTP 安全漏洞 — Nsauditor SpotFTP FTP Password Recovery | 7.5 | High | 2026-02-11 |
| CVE-2020-37207 | Nsasoft SpotDialup 安全漏洞 — Nsauditor SpotDialup | 7.5 | High | 2026-02-11 |
| CVE-2020-37206 | Nsasoft ShareAlarmPro 安全漏洞 — Nsauditor ShareAlarmPro Advanced Network Access Control | 7.5 | High | 2026-02-11 |
| CVE-2020-37205 | Nsasoft RemShutdown 安全漏洞 — Nsauditor RemShutdown | 7.5 | High | 2026-02-11 |
| CVE-2020-37204 | Nsasoft RemShutdown 安全漏洞 — Nsauditor RemShutdown | 7.5 | High | 2026-02-11 |
| CVE-2020-37203 | Nsasoft Office Product Key Finder 安全漏洞 — Nsauditor Office Product Key Finder | 7.5 | High | 2026-02-11 |
| CVE-2020-37202 | Nsasoft NetworkSleuth 安全漏洞 — Nsauditor NetworkSleuth | 7.5 | High | 2026-02-11 |
| CVE-2020-37201 | Nsasoft NetShareWatcher 安全漏洞 — Nsauditor NetShareWatcher | 7.5 | High | 2026-02-11 |
| CVE-2020-37199 | Nsasoft NBMonitor 安全漏洞 — Nsauditor NBMonitor | 7.5 | High | 2026-02-11 |
| CVE-2020-37197 | Nsasoft Dnss Domain Name Search Software 安全漏洞 — Nsauditor Dnss Domain Name Search Software | 7.5 | High | 2026-02-11 |
| CVE-2020-37195 | Nsasoft BlueAuditor 安全漏洞 — BlueAuditor | 7.5 | High | 2026-02-11 |
| CVE-2020-37196 | Nsasoft Dnss Domain Name Search Software 安全漏洞 — Nsauditor Dnss Domain Name Search Software | 7.5 | High | 2026-02-11 |
| CVE-2020-37194 | Nsasoft Backup Key Recovery 安全漏洞 — Nsauditor Backup Key Recovery Recover Keys Crashed Hard Disk Drive | 7.5 | High | 2026-02-11 |
| CVE-2020-37193 | Top Password ZIP Password Recovery 安全漏洞 — ZIP Password Recovery | 7.5 | High | 2026-02-11 |
| CVE-2020-37191 | Top Password Dialup Password Recovery 安全漏洞 — Top Password Software Dialup Password Recovery | 7.5 | High | 2026-02-11 |
| CVE-2020-37190 | Top Password Firefox Password Recovery 安全漏洞 — Top Password Firefox Password Recovery | 7.5 | High | 2026-02-11 |
| CVE-2020-37189 | DigitalVolcano TaskCanvas 安全漏洞 — TaskCanvas | 7.5 | High | 2026-02-11 |
| CVE-2020-37188 | Nsasoft SpotOutlook 安全漏洞 — Nsauditor SpotOutlook | 7.5 | High | 2026-02-11 |
| CVE-2020-37187 | Nsasoft SpotDialup 安全漏洞 — Nsauditor SpotDialup | 7.5 | High | 2026-02-11 |
| CVE-2020-37185 | Nsasoft Backup Key Recovery 安全漏洞 — Nsauditor Backup Key Recovery | 7.5 | High | 2026-02-11 |
| CVE-2020-37180 | Nsasoft GTalk Password Finder 安全漏洞 — Nsauditor GTalk Password Finder | 7.5 | High | 2026-02-11 |
| CVE-2020-37179 | Nsasoft APKF Product Key Finder 安全漏洞 — Nsauditor APKF Product Key Finder | 7.5 | High | 2026-02-11 |
| CVE-2020-37175 | P2PWIFICAM2 安全漏洞 — P2PWIFICAM2 for iOS | 7.5 | High | 2026-02-11 |
| CVE-2025-48723 | QNAP Qsync Central 安全漏洞 — Qsync Central | 9.1 | - | 2026-02-11 |
| CVE-2025-48724 | QNAP Qsync Central 安全漏洞 — Qsync Central | 9.1 | - | 2026-02-11 |
CWE-120(未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)) 是常见的弱点类别,本平台收录该类弱点关联的 1823 条 CVE 漏洞。