CWE-190 整数溢出或超界折返 类弱点 845 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-190 是整数溢出或环绕漏洞,指程序在计算时未考虑数值范围,导致结果超出存储容量并发生回绕。攻击者常通过构造极大输入值,使整数运算结果异常变小,从而绕过安全逻辑或引发缓冲区溢出。开发者应避免假设结果必然大于原值,需在使用前验证输入范围,并采用支持溢出检测的安全库或静态分析工具,确保算术运算在预期范围内安全执行。
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...nresp = packet_get_int(); if (nresp > 0) { response = xmalloc(nresp*sizeof(char*)); for (i = 0; i < nresp; i++) response[i] = packet_get_string(NULL); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-28903 | Volkswagen MIB3 Infotainment 安全漏洞 — Volkswagen MIB3 infotainment system MIB3 OI MQB | 3.3 | Low | 2025-06-28 |
| CVE-2023-28908 | Volkswagen MIB3 Infotainment 安全漏洞 — Volkswagen MIB3 infotainment system MIB3 OI MQB | 5.4 | Medium | 2025-06-28 |
| CVE-2023-28909 | Volkswagen MIB3 Infotainment 安全漏洞 — Volkswagen MIB3 infotainment system MIB3 OI MQB | 8.0 | High | 2025-06-28 |
| CVE-2025-6603 | qCUDA 输入验证错误漏洞 — qCUDA | 5.3 | Medium | 2025-06-25 |
| CVE-2025-52935 | Dragonfly 输入验证错误漏洞 — dragonfly | 8.4AI | HighAI | 2025-06-23 |
| CVE-2025-5475 | Sony XAV-AX8500 输入验证错误漏洞 — XAV-AX8500 | 8.8AI | HighAI | 2025-06-21 |
| CVE-2025-5478 | Sony XAV-AX8500 输入验证错误漏洞 — XAV-AX8500 | 8.8AI | HighAI | 2025-06-21 |
| CVE-2025-49180 | X.org RandR Extension 输入验证错误漏洞 — xwayland | 7.8 | High | 2025-06-17 |
| CVE-2025-49179 | X.org X Record Extension 输入验证错误漏洞 — xwayland | 7.3 | High | 2025-06-17 |
| CVE-2025-49176 | X.org Big Requests 输入验证错误漏洞 — xwayland | 7.3 | High | 2025-06-17 |
| CVE-2025-6196 | libgepub 输入验证错误漏洞 | 5.5 | Medium | 2025-06-17 |
| CVE-2025-6052 | glib 输入验证错误漏洞 — Red Hat Enterprise Linux 10 | 3.7 | Low | 2025-06-13 |
| CVE-2025-6035 | GIMP 缓冲区错误漏洞 | 6.1 | Medium | 2025-06-13 |
| CVE-2025-30327 | Adobe InCopy 输入验证错误漏洞 — InCopy | 7.8 | High | 2025-06-10 |
| CVE-2025-32718 | Microsoft Windows SMB Server 安全漏洞 — Windows 10 Version 1507 | 7.8 | High | 2025-06-10 |
| CVE-2025-5914 | libarchive 资源管理错误漏洞 | 7.8 | High | 2025-06-09 |
| CVE-2025-5916 | libarchive 输入验证错误漏洞 | 3.9 | Low | 2025-06-09 |
| CVE-2025-47712 | Libguestfs nbdkit 输入验证错误漏洞 | 6.5 | Medium | 2025-06-09 |
| CVE-2025-5473 | GIMP 输入验证错误漏洞 — GIMP | 7.8AI | HighAI | 2025-06-06 |
| CVE-2024-52035 | Catdoc 安全漏洞 — catdoc | 8.4 | High | 2025-06-02 |
| CVE-2025-1235 | WAGO Fully Managed Switches 输入验证错误漏洞 — Fully Managed Switches 0852-0303 | 4.3 | Medium | 2025-06-02 |
| CVE-2025-47294 | Fortinet FortiOS 输入验证错误漏洞 — FortiOS | 4.8 | Medium | 2025-05-28 |
| CVE-2024-23337 | jq 输入验证错误漏洞 — jq | 4.3 | Medium | 2025-05-21 |
| CVE-2025-5001 | GNU PSPP 输入验证错误漏洞 — PSPP | 3.3 | Low | 2025-05-20 |
| CVE-2025-4945 | libsoup 输入验证错误漏洞 | 3.7 | Low | 2025-05-19 |
| CVE-2025-48175 | libavif 安全漏洞 — libavif | 4.5 | Medium | 2025-05-16 |
| CVE-2025-48174 | libavif 安全漏洞 — libavif | 4.5 | Medium | 2025-05-16 |
| CVE-2025-43547 | Adobe Bridge 输入验证错误漏洞 — Bridge | 7.8 | High | 2025-05-13 |
| CVE-2025-43556 | Adobe Animate 输入验证错误漏洞 — Animate | 7.8 | High | 2025-05-13 |
| CVE-2025-30325 | Adobe Photoshop 输入验证错误漏洞 — Photoshop Desktop | 7.8 | High | 2025-05-13 |
CWE-190(整数溢出或超界折返) 是常见的弱点类别,本平台收录该类弱点关联的 845 条 CVE 漏洞。