CWE-126 缓冲区上溢读取 类弱点 494 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-126 缓冲区过读是一种内存安全漏洞,指程序通过索引或指针访问了目标缓冲区之后的非法内存区域。攻击者利用此缺陷可读取敏感数据或引发程序崩溃,进而可能导致信息泄露或拒绝服务。开发者应避免此类问题,需严格验证内存访问边界,确保读写操作不超出缓冲区合法范围,并采用安全的内存管理函数以防止越界访问。
int processMessageFromSocket(int socket) { int success; char buffer[BUFFER_SIZE]; char message[MESSAGE_SIZE]; // get message from socket and store into buffer //Ignoring possibliity that buffer > BUFFER_SIZE if (getMessage(socket, buffer, BUFFER_SIZE) > 0) { // place contents of the buffer into message structure ExMessage *msg = recastBuffer(buffer); // copy message body into string for processing int index; for (index = 0; index < msg->msgLength; index++) { message[index] = msg->msgBody[index]; } message[index] = '\0'; // process message success = processMessage(message); } return success; }
int main(int argc, char **argv) { char Filename[256]; char Pattern[32]; /* Validate number of parameters and ensure valid content */ ... /* copy filename parameter to variable, may cause off-by-one overflow */ strncpy(Filename, argv[1], sizeof(Filename)); /* copy pattern parameter to variable, may cause off-by-one overflow */ strncpy(Pattern, argv[2], sizeof(Pattern)); printf("Searching file: %s for the pattern: %s\n", Filename, Pattern); Scan_File(Filename, Pattern); }
/* copy filename parameter to variable, no off-by-one overflow */ strncpy(Filename, argv[2], sizeof(Filename)-1); Filename[255]='\0'; /* copy pattern parameter to variable, no off-by-one overflow */ strncpy(Pattern, argv[3], sizeof(Pattern)-1); Pattern[31]='\0';
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-53806 | Microsoft Windows Routing and Remote Access Service 安全漏洞 — Windows Server 2008 R2 Service Pack 1 | 6.5 | Medium | 2025-09-09 |
| CVE-2025-53796 | Microsoft Windows Routing and Remote Access Service 安全漏洞 — Windows Server 2008 R2 Service Pack 1 | 6.5 | Medium | 2025-09-09 |
| CVE-2025-53797 | Microsoft Windows Routing and Remote Access Service 安全漏洞 — Windows Server 2008 R2 Service Pack 1 | 6.5 | Medium | 2025-09-09 |
| CVE-2025-53798 | Microsoft Windows Routing and Remote Access Service 安全漏洞 — Windows Server 2008 R2 Service Pack 1 | 6.5 | Medium | 2025-09-09 |
| CVE-2025-36855 | Microsoft .NET 安全漏洞 — .NET 6.0 | 8.8 | High | 2025-09-08 |
| CVE-2025-53736 | Microsoft Word 安全漏洞 — Microsoft 365 Apps for Enterprise | 6.8 | Medium | 2025-08-12 |
| CVE-2025-27068 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.8 | High | 2025-08-06 |
| CVE-2025-27065 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.5 | High | 2025-08-06 |
| CVE-2025-21457 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 6.1 | Medium | 2025-08-06 |
| CVE-2023-53159 | rust-openssl 安全漏洞 — openssl | 4.5 | Medium | 2025-07-28 |
| CVE-2025-7745 | ABB AC500 V2 安全漏洞 — AC500 V2 | 5.8 | Medium | 2025-07-24 |
| CVE-2025-49684 | Microsoft Windows Storage Port Driver 安全漏洞 — Windows 10 Version 1507 | 5.5 | Medium | 2025-07-08 |
| CVE-2025-49659 | Microsoft Windows 安全漏洞 — Windows 10 Version 1507 | 7.8 | High | 2025-07-08 |
| CVE-2025-47973 | Microsoft Virtual Hard Disks 安全漏洞 — Windows 10 Version 1507 | 7.8 | High | 2025-07-08 |
| CVE-2025-47971 | Microsoft Virtual Hard Disk 安全漏洞 — Windows 10 Version 1507 | 7.8 | High | 2025-07-08 |
| CVE-2025-27057 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.5 | High | 2025-07-08 |
| CVE-2025-27055 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.8 | High | 2025-07-08 |
| CVE-2025-21454 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.5 | High | 2025-07-08 |
| CVE-2025-21449 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.5 | High | 2025-07-08 |
| CVE-2025-21446 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.5 | High | 2025-07-08 |
| CVE-2025-21427 | Payload和form 安全漏洞 — Snapdragon | 8.2 | High | 2025-07-08 |
| CVE-2025-24068 | Microsoft Windows 安全漏洞 — Windows 10 Version 1507 | 5.5 | Medium | 2025-06-10 |
| CVE-2025-27029 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.5 | High | 2025-06-03 |
| CVE-2025-21463 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.5 | High | 2025-06-03 |
| CVE-2024-53026 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.2 | High | 2025-06-03 |
| CVE-2024-53021 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.2 | High | 2025-06-03 |
| CVE-2024-53020 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.2 | High | 2025-06-03 |
| CVE-2024-53019 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.2 | High | 2025-06-03 |
| CVE-2025-47295 | Fortinet FortiOS 安全漏洞 — FortiOS | 3.4 | Low | 2025-05-28 |
| CVE-2025-32704 | Microsoft Excel 安全漏洞 — Microsoft 365 Apps for Enterprise | 8.4 | High | 2025-05-13 |
CWE-126(缓冲区上溢读取) 是常见的弱点类别,本平台收录该类弱点关联的 494 条 CVE 漏洞。