目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-191 整数下溢(超界折返) 类漏洞列表 307

CWE-191 整数下溢(超界折返) 类弱点 307 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-191 整数下溢漏洞发生于程序执行减法操作时,结果低于整数类型允许的最小值,导致数值回绕至最大值附近,产生非预期结果。攻击者常利用此缺陷绕过安全检查或引发逻辑错误,进而可能导致缓冲区溢出等更严重的安全问题。开发者应通过添加边界检查、使用更大范围的整数类型或启用编译器的溢出检测功能,确保算术运算在合法范围内,从而有效防止此类漏洞发生。

MITRE CWE 官方描述
CWE:CWE-191 整数下溢(Integer Underflow)(回绕或回绕现象 Wrap or Wraparound) 产品从一个值中减去另一个值,导致结果小于允许的最小整数值,从而产生一个不等于正确结果的值。 这种情况可能发生在有符号(signed)和无符号(unsigned)情形中。
常见影响 (3)
Availability DoS: Crash, Exit, or Restart, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Instability
This weakness will generally lead to undefined behavior and therefore crashes. In the case of overflows involving loop index variables, the likelihood of infinite loops is also high.
Integrity Modify Memory
If the value in question is important to data (as opposed to flow), simple data corruption has occurred. Also, if the wrap around results in other conditions such as buffer overflows, further memory corruption may occur.
Confidentiality, Availability, Access Control Execute Unauthorized Code or Commands, Bypass Protection Mechanism
This weakness can sometimes trigger buffer overflows which can be used to execute arbitrary code. This is usually outside the scope of a program's implicit security policy.
代码示例 (2)
The following example subtracts from a 32 bit signed integer.
#include <stdio.h> #include <stdbool.h> main (void) { int i; i = -2147483648; i = i - 1; return 0; }
Bad · C
This code performs a stack allocation based on a length calculation.
int a = 5, b = 6; size_t len = a - b; char buf[len];    // Just blows up the stack }
Bad · C
CVE ID 标题 CVSS 风险等级 Published
CVE-2023-38162 Microsoft Windows DHCP Server 资源管理错误漏洞 — Windows Server 2019 7.5 High 2023-09-12
CVE-2023-39350 FreeRDP 数字错误漏洞 — FreeRDP 5.9 Medium 2023-08-31
CVE-2023-35387 Microsoft Windows Bluetooth A2DP driver 安全漏洞 — Windows 10 Version 1507 8.8 High 2023-08-08
CVE-2023-36909 Microsoft Message Queuing 安全漏洞 — Windows 10 Version 1507 6.5 Medium 2023-08-08
CVE-2022-28733 grub2 数字错误漏洞 — GNU GRUB 8.1 High 2023-07-20
CVE-2023-33158 Microsoft Excel 安全漏洞 — Microsoft Office 2019 for Mac 7.8 High 2023-07-11
CVE-2023-29349 Microsoft ODBC Driver 安全漏洞 — Microsoft OLE DB Driver 18 for SQL Server 7.8 High 2023-06-16
CVE-2023-32014 Microsoft Windows PGM 安全漏洞 — Windows 10 Version 1809 9.8 Critical 2023-06-13
CVE-2023-31137 MaraDNS 数字错误漏洞 — MaraDNS 7.5 High 2023-05-09
CVE-2023-24821 RIOT RIOT-OS 数字错误漏洞 — RIOT 7.5 High 2023-04-24
CVE-2023-24820 RIOT RIOT-OS 数字错误漏洞 — RIOT 7.5 High 2023-04-24
CVE-2023-26421 Adobe Acrobat Reader 数字错误漏洞 — Acrobat Reader 7.8 High 2023-04-12
CVE-2023-28293 Microsoft Windows Kernel 安全漏洞 — Windows 10 Version 1809 7.8 High 2023-04-11
CVE-2023-28250 Microsoft Windows PGM 安全漏洞 — Windows 10 Version 1809 9.8 Critical 2023-04-11
CVE-2023-28272 Microsoft Windows Kernel 安全漏洞 — Windows 10 Version 1809 7.8 High 2023-04-11
CVE-2023-28247 Microsoft Windows Network File System 安全漏洞 — Windows Server 2019 7.5 High 2023-04-11
CVE-2023-24887 Microsoft PostScript Printer Driver安全漏洞 — Windows 10 Version 1809 8.8 High 2023-04-11
CVE-2023-21630 Qualcomm Chipsets 输入验证错误漏洞 — Snapdragon 8.4 High 2023-04-04
CVE-2023-24911 Microsoft PostScript Printer Driver 安全漏洞 — Windows 10 Version 1809 4.3 Medium 2023-03-14
CVE-2023-24864 Microsoft PostScript Printer Driver 安全漏洞 — Windows 10 Version 1809 8.8 High 2023-03-14
CVE-2023-21708 Microsoft Windows Remote Procedure Call 安全漏洞 — Windows 10 Version 1809 9.8 Critical 2023-03-14
CVE-2023-21815 Microsoft Visual Studio 安全漏洞 — Microsoft Visual Studio 2013 Update 5 7.8 High 2023-02-14
CVE-2023-21718 Microsoft SQL Server 安全漏洞 — Microsoft SQL Server 2008 R2 Service Pack 3 (QFE) 7.8 High 2023-02-14
CVE-2023-21684 Microsoft PostScript Printer Driver 安全漏洞 — Windows 10 Version 1507 8.8 High 2023-02-14
CVE-2023-0469 Linux kernel 资源管理错误漏洞 — Kernel 5.5 - 2023-01-25
CVE-2023-21681 Microsoft OLE DB Provider for SQL Server 安全漏洞 — Windows 10 Version 1809 8.8 High 2023-01-10
CVE-2023-21556 Microsoft Windows 安全漏洞 — Windows 10 Version 1809 8.1 High 2023-01-10
CVE-2023-21527 Microsoft Windows 安全漏洞 — Windows 10 Version 1809 7.5 High 2023-01-10
CVE-2022-44444 Google Android OS和unisoc部分产品数字错误漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 5.5 - 2023-01-04
CVE-2022-37301 Schneider Electric Modicon M340 数字错误漏洞 — Modicon M340 CPU (part numbers BMXP34*) 7.5 High 2022-11-22

CWE-191(整数下溢(超界折返)) 是常见的弱点类别,本平台收录该类弱点关联的 307 条 CVE 漏洞。