CWE-190 整数溢出或超界折返 类弱点 845 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-190 是整数溢出或环绕漏洞,指程序在计算时未考虑数值范围,导致结果超出存储容量并发生回绕。攻击者常通过构造极大输入值,使整数运算结果异常变小,从而绕过安全逻辑或引发缓冲区溢出。开发者应避免假设结果必然大于原值,需在使用前验证输入范围,并采用支持溢出检测的安全库或静态分析工具,确保算术运算在预期范围内安全执行。
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...nresp = packet_get_int(); if (nresp > 0) { response = xmalloc(nresp*sizeof(char*)); for (i = 0; i < nresp; i++) response[i] = packet_get_string(NULL); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-7709 | SQLite FTS5 安全漏洞 — FTS5 | 9.8AI | CriticalAI | 2025-09-08 |
| CVE-2025-36853 | Microsoft .NET和Microsoft Visual Studio 安全漏洞 — .NET 6.0 | 7.5 | High | 2025-09-08 |
| CVE-2023-31365 | AMD Graphics Driver 安全漏洞 — AMD Radeon™ RX 7000 Series Graphics Products | 3.9 | Low | 2025-09-06 |
| CVE-2021-46750 | AMD Graphics Driver、AMD Embedded Processors和AMD Client Processor 安全漏洞 — AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics | 3.0 | Low | 2025-09-06 |
| CVE-2021-26377 | AMD多款产品 安全漏洞 — AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics | 4.1 | Medium | 2025-09-06 |
| CVE-2025-9688 | Mupen64Plus 安全漏洞 — Mupen64Plus | 5.0 | Medium | 2025-08-30 |
| CVE-2025-53518 | libbiosig 输入验证错误漏洞 — libbiosig | 9.8 | Critical | 2025-08-25 |
| CVE-2025-52581 | libbiosig 输入验证错误漏洞 — libbiosig | 9.8 | Critical | 2025-08-25 |
| CVE-2025-55154 | ImageMagick 输入验证错误漏洞 — ImageMagick | 8.8 | High | 2025-08-13 |
| CVE-2025-25248 | Fortinet多款产品 输入验证错误漏洞 — FortiOS | 4.8 | Medium | 2025-08-12 |
| CVE-2025-50166 | Microsoft Windows 输入验证错误漏洞 — Windows 10 Version 1507 | 6.5 | Medium | 2025-08-12 |
| CVE-2024-38805 | EDK2 安全漏洞 — EDK2 | 6.3 | Medium | 2025-08-12 |
| CVE-2025-23327 | NVIDIA Triton Inference Server 输入验证错误漏洞 — Triton Inference Server | 7.5 | High | 2025-08-06 |
| CVE-2025-23324 | NVIDIA Triton Inference Server 输入验证错误漏洞 — Triton Inference Server | 7.5 | High | 2025-08-06 |
| CVE-2025-23323 | NVIDIA Triton Inference Server 输入验证错误漏洞 — Triton Inference Server | 7.5 | High | 2025-08-06 |
| CVE-2025-54631 | Huawei HarmonyOS和Huawei EMUI 安全漏洞 — HarmonyOS | 6.7 | Medium | 2025-08-06 |
| CVE-2025-54804 | Russh 安全漏洞 — russh | 6.5 | Medium | 2025-08-05 |
| CVE-2025-7458 | SQLite 安全漏洞 — SQLite | 9.1 | - | 2025-07-29 |
| CVE-2024-58263 | cosmwasm-std crate 输入验证错误漏洞 — cosmwasm-std | 3.7 | Low | 2025-07-27 |
| CVE-2023-53156 | transpose crate 输入验证错误漏洞 — transpose | 4.5 | Medium | 2025-07-27 |
| CVE-2025-5449 | libssh 输入验证错误漏洞 | 6.5 | Medium | 2025-07-25 |
| CVE-2025-48964 | iputils 输入验证错误漏洞 — iputils | 6.5 | Medium | 2025-07-22 |
| CVE-2025-52520 | Apache Tomcat 输入验证错误漏洞 — Apache Tomcat | 7.5 | - | 2025-07-10 |
| CVE-2025-49531 | Adobe Illustrator 输入验证错误漏洞 — Illustrator | 7.8 | High | 2025-07-08 |
| CVE-2025-49742 | Microsoft Graphics Component 安全漏洞 — Windows 10 Version 1507 | 7.8 | High | 2025-07-08 |
| CVE-2025-49683 | Microsoft Manage Virtual Hard Disks 安全漏洞 — Windows 10 Version 1507 | 7.8 | High | 2025-07-08 |
| CVE-2025-48816 | Microsoft Windows 输入验证错误漏洞 — Windows 10 Version 1507 | 7.8 | High | 2025-07-08 |
| CVE-2025-48002 | Microsoft Hyper-V 输入验证错误漏洞 — Windows 11 Version 24H2 | 5.7 | Medium | 2025-07-08 |
| CVE-2025-49689 | Microsoft Virtual Hard Disk 安全漏洞 — Windows 10 Version 1507 | 7.8 | High | 2025-07-08 |
| CVE-2025-48172 | CHMLib 输入验证错误漏洞 — CHMLib | 5.6 | Medium | 2025-07-04 |
CWE-190(整数溢出或超界折返) 是常见的弱点类别,本平台收录该类弱点关联的 845 条 CVE 漏洞。