CWE-190 整数溢出或超界折返 类弱点 861 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-190 是整数溢出或环绕漏洞,指程序在计算时未考虑数值范围,导致结果超出存储容量并发生回绕。攻击者常通过构造极大输入值,使整数运算结果异常变小,从而绕过安全逻辑或引发缓冲区溢出。开发者应避免假设结果必然大于原值,需在使用前验证输入范围,并采用支持溢出检测的安全库或静态分析工具,确保算术运算在预期范围内安全执行。
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...nresp = packet_get_int(); if (nresp > 0) { response = xmalloc(nresp*sizeof(char*)); for (i = 0; i < nresp; i++) response[i] = packet_get_string(NULL); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-2809 | Netskope Endpoint DLP Module 安全漏洞 — Endpoint DLP Module for Netskope Client | 4.4AI | MediumAI | 2026-03-17 |
| CVE-2025-15584 | Netskope Client 安全漏洞 — Endpoint DLP Module for Netskope Client | 5.5AI | MediumAI | 2026-03-17 |
| CVE-2026-2921 | GStreamer 输入验证错误漏洞 — GStreamer | 7.8 | - | 2026-03-13 |
| CVE-2026-31814 | Yamux 输入验证错误漏洞 — rust-yamux | 7.5 | - | 2026-03-13 |
| CVE-2026-29776 | FreeRDP 安全漏洞 — FreeRDP | 3.1 | Low | 2026-03-13 |
| CVE-2026-27281 | Adobe DNG SDK 输入验证错误漏洞 — DNG SDK | 5.5 | Medium | 2026-03-10 |
| CVE-2026-26134 | Microsoft Office 资源管理错误漏洞 — Microsoft Office for Android | 7.8 | High | 2026-03-10 |
| CVE-2026-26111 | Microsoft Windows Routing and Remote Access Service 输入验证错误漏洞 — Windows 10 Version 1607 | 8.0 | High | 2026-03-10 |
| CVE-2026-25173 | Microsoft Windows Routing and Remote Access Service 输入验证错误漏洞 — Windows 10 Version 1607 | 8.0 | High | 2026-03-10 |
| CVE-2026-25172 | Microsoft Windows Routing and Remote Access Service 输入验证错误漏洞 — Windows 10 Version 1607 | 8.0 | High | 2026-03-10 |
| CVE-2026-28493 | ImageMagick 输入验证错误漏洞 — ImageMagick | 6.5 | Medium | 2026-03-09 |
| CVE-2026-3707 | WebP4j 输入验证错误漏洞 — webp4j | 5.3 | Medium | 2026-03-08 |
| CVE-2026-30910 | Crypt::Sodium::XS 安全漏洞 — Crypt::Sodium::XS | 7.5 | - | 2026-03-08 |
| CVE-2026-30909 | Crypt::NaCl::Sodium 安全漏洞 — Crypt::NaCl::Sodium | 9.1 | - | 2026-03-08 |
| CVE-2026-28497 | TinyWeb 环境问题漏洞 — TinyWeb | 6.5 | - | 2026-03-06 |
| CVE-2026-20025 | Cisco Secure Firewall Adaptive Security Appliance和Cisco Secure Firewall Threat Defense 输入验证错误漏洞 — Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 6.8 | Medium | 2026-03-04 |
| CVE-2025-66168 | Apache ActiveMQ 安全漏洞 — Apache ActiveMQ | 5.4 | Medium | 2026-03-04 |
| CVE-2026-21385 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 7.8 | High | 2026-03-02 |
| CVE-2026-3284 | libvips 输入验证错误漏洞 — libvips | 3.3 | Low | 2026-02-27 |
| CVE-2026-27951 | FreeRDP 输入验证错误漏洞 — FreeRDP | 5.3 | Medium | 2026-02-25 |
| CVE-2026-27691 | iccDEV 安全漏洞 — iccDEV | 6.2 | Medium | 2026-02-25 |
| CVE-2026-25989 | ImageMagick 安全漏洞 — ImageMagick | 7.5 | High | 2026-02-24 |
| CVE-2026-25970 | ImageMagick 输入验证错误漏洞 — ImageMagick | 5.3 | Medium | 2026-02-24 |
| CVE-2026-2588 | Crypt::NaCl::Sodium 安全漏洞 — Crypt::NaCl::Sodium | 9.1AI | CriticalAI | 2026-02-22 |
| CVE-2026-0619 | Silicon Labs Matter SDK 安全漏洞 — Silicon Labs Matter | 7.5AI | HighAI | 2026-02-12 |
| CVE-2024-36320 | AMD Graphics Driver 安全漏洞 — AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics | 7.8AI | HighAI | 2026-02-11 |
| CVE-2024-36316 | AMD Graphics Driver 安全漏洞 — AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics; AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics | 5.5 | Medium | 2026-02-11 |
| CVE-2025-48515 | AMD Ryzen 安全漏洞 — AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics | 7.8AI | HighAI | 2026-02-10 |
| CVE-2026-21354 | Adobe DNG SDK 输入验证错误漏洞 — DNG SDK | 5.5 | Medium | 2026-02-10 |
| CVE-2026-21353 | Adobe DNG SDK 输入验证错误漏洞 — DNG SDK | 7.8 | High | 2026-02-10 |
CWE-190(整数溢出或超界折返) 是常见的弱点类别,本平台收录该类弱点关联的 861 条 CVE 漏洞。