CWE-125 跨界内存读 类弱点 2941 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-125 越界读取属于内存安全漏洞,指程序访问了缓冲区边界之外的内存区域。攻击者利用此缺陷可读取敏感数据或引发信息泄露,甚至通过特定构造触发逻辑错误以辅助后续攻击。开发者应严格实施边界检查,确保索引在有效范围内,并使用支持自动边界检测的高级语言或静态分析工具,从源头杜绝非法内存访问。
int getValueFromArray(int *array, int len, int index) { int value; // check that the array index is less than the maximum // length of the array if (index < len) { // get the value at the specified index of the array value = array[index]; } // if array index is invalid then output error message // and return value indicating error else { printf("Value is: %d\n", array[index]); value = -1; } return value; }... // check that the array index is within the correct // range of values for the array if (index >= 0 && index < len) { ...int processMessageFromSocket(int socket) { int success; char buffer[BUFFER_SIZE]; char message[MESSAGE_SIZE]; // get message from socket and store into buffer //Ignoring possibliity that buffer > BUFFER_SIZE if (getMessage(socket, buffer, BUFFER_SIZE) > 0) { // place contents of the buffer into message structure ExMessage *msg = recastBuffer(buffer); // copy message body into string for processing int index; for (index = 0; index < msg->msgLength; index++) { message[index] = msg->msgBody[index]; } message[index] = '\0'; // process message success = processMessage(message); } return success; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2018-9973 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 6.5 | - | 2018-05-17 |
| CVE-2018-9976 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 6.5 | - | 2018-05-17 |
| CVE-2018-9978 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 6.5 | - | 2018-05-17 |
| CVE-2018-9979 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 6.5 | - | 2018-05-17 |
| CVE-2018-9980 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 6.5 | - | 2018-05-17 |
| CVE-2018-9983 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 6.5 | - | 2018-05-17 |
| CVE-2018-9984 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 6.5 | - | 2018-05-17 |
| CVE-2017-14461 | Dovecot 缓冲区错误漏洞 — Dovecot | 7.1 | - | 2018-03-02 |
| CVE-2018-5380 | Quagga BGP daemon 安全漏洞 — bgpd | 4.3 | - | 2018-02-19 |
| CVE-2017-10956 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-14818 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-14819 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-14820 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-14821 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-14822 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-16573 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-16574 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-16579 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-16580 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-16584 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-16588 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-16589 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-12-20 |
| CVE-2017-10942 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-10-31 |
| CVE-2017-10943 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-10-31 |
| CVE-2017-10944 | Foxit Reader 安全漏洞 — Foxit Reader | 6.5 | - | 2017-10-31 |
| CVE-2017-9283 | Micro Focus VisiBroker 安全漏洞 — Micro Focus VisiBroker | 9.8 | - | 2017-09-21 |
| CVE-2017-7544 | libexif 安全漏洞 — libexif | 9.1 | - | 2017-09-21 |
| CVE-2017-9117 | Silicon Graphics LibTIFF 安全漏洞 — LibTIFF | 4.0 | Medium | 2017-05-21 |
| CVE-2016-9036 | Tarantool Msgpuck 安全漏洞 — Msgpuck library | 7.5 | - | 2016-12-23 |
| CVE-2016-9037 | Tarantool 安全漏洞 — Tarantool | 7.5 | - | 2016-12-23 |
CWE-125(跨界内存读) 是常见的弱点类别,本平台收录该类弱点关联的 2941 条 CVE 漏洞。