CWE-787 跨界内存写 类弱点 2273 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-787 越界写入是一种严重的内存安全漏洞,指程序向缓冲区边界之外或起始位置之前写入数据。攻击者利用此缺陷可覆盖相邻内存,导致程序崩溃、数据损坏,甚至通过精心构造的 payload 实现任意代码执行,从而完全控制目标系统。开发者应避免此类风险,需严格实施边界检查,使用安全的内存管理函数,启用编译器防护机制,并遵循最小权限原则,确保所有内存访问均在合法范围内。
int id_sequence[3]; /* Populate the id array. */ id_sequence[0] = 123; id_sequence[1] = 234; id_sequence[2] = 345; id_sequence[3] = 456;int returnChunkSize(void *) { /* if chunk info is valid, return the size of usable memory, * else, return -1 to indicate an error */ ... } int main() { ... memcpy(destBuf, srcBuf, (returnChunkSize(destBuf)-1)); ... }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2018-3860 | ACD Systems Canvas Draw 缓冲区错误漏洞 — Canvas Draw | 7.8 | - | 2018-07-19 |
| CVE-2018-3870 | ACD Systems Canvas Draw 缓冲区错误漏洞 — Canvas Draw | 7.8 | - | 2018-07-19 |
| CVE-2018-3871 | ACD Systems Canvas Draw 缓冲区错误漏洞 — Canvas Draw | 7.8 | - | 2018-07-19 |
| CVE-2017-7467 | Minicom 缓冲区错误漏洞 — minicom | 9.8 | - | 2018-07-11 |
| CVE-2017-2615 | QEMU 安全漏洞 — display | 8.8 | - | 2018-07-02 |
| CVE-2018-10473 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 8.8 | - | 2018-05-17 |
| CVE-2018-10474 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 8.8 | - | 2018-05-17 |
| CVE-2018-10477 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 8.8 | - | 2018-05-17 |
| CVE-2018-10483 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 8.8 | - | 2018-05-17 |
| CVE-2018-10489 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 8.8 | - | 2018-05-17 |
| CVE-2018-10491 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 8.8 | - | 2018-05-17 |
| CVE-2018-1176 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 8.8 | - | 2018-05-17 |
| CVE-2018-9982 | Foxit Reader 缓冲区错误漏洞 — Foxit Reader | 8.8 | - | 2018-05-17 |
| CVE-2018-7509 | Delta Electronics WPLSoft 安全漏洞 — Delta Electronics WPLSoft | 8.8 | - | 2018-05-04 |
| CVE-2018-8837 | Advantech WebAccess HMI Designer 安全漏洞 — Advantech WebAccess HMI Designer | 7.8 | - | 2018-04-25 |
| CVE-2017-9634 | Mitsubishi Electric E-Designer 安全漏洞 — E-Designer | 9.8 | - | 2018-04-17 |
| CVE-2018-7517 | Omron CX-Supervisor 缓冲区错误漏洞 — Omron CX-Supervisor | 5.3 | - | 2018-03-21 |
| CVE-2018-1171 | Joyent SmartOS 缓冲区错误漏洞 — Joyent SmartOS | 7.0 | - | 2018-03-19 |
| CVE-2017-16747 | Delta Industrial Automation Screen Editor 安全漏洞 — Delta Electronics Delta Industrial Automation Screen Editor | 7.8 | - | 2018-03-15 |
| CVE-2017-17410 | Bitdefender Internet Security 安全漏洞 — Bitdefender Internet Security | 8.8 | - | 2017-12-21 |
| CVE-2017-9938 | Siemens SIMATIC Logon 安全漏洞 — SIMATIC Logon All versions before V1.6 | 7.5 | - | 2017-08-08 |
| CVE-2017-7523 | Cygwin 缓冲区错误漏洞 — cygwin | 7.5 | - | 2017-07-21 |
| CVE-2017-6867 | 多款Siemens产品输入验证漏洞 — Siemens SIMATIC WinCC | 4.9 | - | 2017-05-11 |
CWE-787(跨界内存写) 是常见的弱点类别,本平台收录该类弱点关联的 2273 条 CVE 漏洞。