CWE-190 整数溢出或超界折返 类弱点 845 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-190 是整数溢出或环绕漏洞,指程序在计算时未考虑数值范围,导致结果超出存储容量并发生回绕。攻击者常通过构造极大输入值,使整数运算结果异常变小,从而绕过安全逻辑或引发缓冲区溢出。开发者应避免假设结果必然大于原值,需在使用前验证输入范围,并采用支持溢出检测的安全库或静态分析工具,确保算术运算在预期范围内安全执行。
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...nresp = packet_get_int(); if (nresp > 0) { response = xmalloc(nresp*sizeof(char*)); for (i = 0; i < nresp; i++) response[i] = packet_get_string(NULL); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-34353 | ocaml 输入验证错误漏洞 — OCaml | 5.9 | Medium | 2026-03-27 |
| CVE-2026-2272 | GIMP 安全漏洞 — Red Hat Enterprise Linux 6 | 4.3 | Medium | 2026-03-26 |
| CVE-2026-2271 | GIMP 安全漏洞 — Red Hat Enterprise Linux 6 | 3.3 | Low | 2026-03-26 |
| CVE-2026-27889 | Nats-Server 输入验证错误漏洞 — nats-server | 7.5 | High | 2026-03-25 |
| CVE-2026-4775 | LibTIFF 输入验证错误漏洞 — Red Hat Enterprise Linux 10 | 7.8 | High | 2026-03-24 |
| CVE-2026-27784 | F5 NGINX Open Source 输入验证错误漏洞 — NGINX Open Source | 7.8 | High | 2026-03-24 |
| CVE-2026-33855 | Android ImageMagick 安全漏洞 — Android-ImageMagick7 | 5.5 | Medium | 2026-03-24 |
| CVE-2026-4739 | ITK 安全漏洞 — ITK | 8.8 | - | 2026-03-24 |
| CVE-2026-4731 | ART 安全漏洞 — ART | 7.8 | - | 2026-03-24 |
| CVE-2026-33306 | bcrypt-ruby 输入验证错误漏洞 — bcrypt-ruby | 7.5 | - | 2026-03-24 |
| CVE-2026-32845 | cgltf 安全漏洞 — cgltf | 8.4 | High | 2026-03-23 |
| CVE-2026-33040 | rust-libp2p 输入验证错误漏洞 — rust-libp2p | 7.5 | - | 2026-03-20 |
| CVE-2026-32875 | UltraJSON 安全漏洞 — ultrajson | 7.5 | High | 2026-03-20 |
| CVE-2026-32759 | File Browser 输入验证错误漏洞 — filebrowser | 8.1 | - | 2026-03-19 |
| CVE-2026-2809 | Netskope Endpoint DLP Module 安全漏洞 — Endpoint DLP Module for Netskope Client | 4.4AI | MediumAI | 2026-03-17 |
| CVE-2025-15584 | Netskope Client 安全漏洞 — Endpoint DLP Module for Netskope Client | 5.5AI | MediumAI | 2026-03-17 |
| CVE-2026-2921 | GStreamer 输入验证错误漏洞 — GStreamer | 7.8 | - | 2026-03-13 |
| CVE-2026-31814 | Yamux 输入验证错误漏洞 — rust-yamux | 7.5 | - | 2026-03-13 |
| CVE-2026-29776 | FreeRDP 安全漏洞 — FreeRDP | 3.1 | Low | 2026-03-13 |
| CVE-2026-27281 | Adobe DNG SDK 输入验证错误漏洞 — DNG SDK | 5.5 | Medium | 2026-03-10 |
| CVE-2026-26134 | Microsoft Office 资源管理错误漏洞 — Microsoft Office for Android | 7.8 | High | 2026-03-10 |
| CVE-2026-26111 | Microsoft Windows Routing and Remote Access Service 输入验证错误漏洞 — Windows 10 Version 1607 | 8.0 | High | 2026-03-10 |
| CVE-2026-25173 | Microsoft Windows Routing and Remote Access Service 输入验证错误漏洞 — Windows 10 Version 1607 | 8.0 | High | 2026-03-10 |
| CVE-2026-25172 | Microsoft Windows Routing and Remote Access Service 输入验证错误漏洞 — Windows 10 Version 1607 | 8.0 | High | 2026-03-10 |
| CVE-2026-28493 | ImageMagick 输入验证错误漏洞 — ImageMagick | 6.5 | Medium | 2026-03-09 |
| CVE-2026-3707 | WebP4j 输入验证错误漏洞 — webp4j | 5.3 | Medium | 2026-03-08 |
| CVE-2026-30910 | Crypt::Sodium::XS 安全漏洞 — Crypt::Sodium::XS | 7.5 | - | 2026-03-08 |
| CVE-2026-30909 | Crypt::NaCl::Sodium 安全漏洞 — Crypt::NaCl::Sodium | 9.1 | - | 2026-03-08 |
| CVE-2026-28497 | TinyWeb 环境问题漏洞 — TinyWeb | 6.5 | - | 2026-03-06 |
| CVE-2026-20025 | Cisco Secure Firewall Adaptive Security Appliance和Cisco Secure Firewall Threat Defense 输入验证错误漏洞 — Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 6.8 | Medium | 2026-03-04 |
CWE-190(整数溢出或超界折返) 是常见的弱点类别,本平台收录该类弱点关联的 845 条 CVE 漏洞。