CWE-124 缓冲区下溢 类弱点 29 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-124 缓冲区下溢是一种内存破坏漏洞,指程序通过索引或指针向缓冲区起始地址之前的内存位置写入数据。攻击者利用此缺陷可覆盖关键数据结构或控制流信息,从而引发程序崩溃或执行任意代码。开发者应避免使用未经验证的负索引,实施严格的边界检查,并采用支持自动内存安全检测的现代编程语言或库,以从根本上防止此类越界写入行为。
char* trimTrailingWhitespace(char *strMessage, int length) { char *retMessage; char *message = malloc(sizeof(char)*(length+1)); // copy input string to a temporary string char message[length+1]; int index; for (index = 0; index < length; index++) { message[index] = strMessage[index]; } message[index] = '\0'; // trim trailing whitespace int len = index-1; while (isspace(message[len])) { message[len] = '\0'; len--; } // return string without trailing whitespace retMessage = message; return retMessage; }int main() { ... char *result = strstr(destBuf, "Replace Me"); int idx = result - destBuf; strcpy(&destBuf[idx], srcBuf); ... }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-41499 | Wazuh 安全漏洞 — wazuh | 6.5 | Medium | 2026-04-29 |
| CVE-2026-26204 | Wazuh 安全漏洞 — wazuh | 4.4 | Medium | 2026-04-29 |
| CVE-2026-0966 | libssh 安全漏洞 — Red Hat Hardened Images | 7.5AI | HighAI | 2026-03-26 |
| CVE-2026-20104 | Cisco多款产品 安全漏洞 — Cisco IOS XE Software | 6.1 | Medium | 2026-03-25 |
| CVE-2026-28419 | Vim 安全漏洞 — vim | 5.3 | Medium | 2026-02-27 |
| CVE-2024-36310 | AMD多款产品 安全漏洞 — AMD EPYC™ 9004 Series Processors | 6.7AI | MediumAI | 2026-02-10 |
| CVE-2026-1485 | glib 缓冲区错误漏洞 — Red Hat Enterprise Linux 10 | 2.8 | Low | 2026-01-27 |
| CVE-2025-68114 | Capstone 安全漏洞 — capstone | 4.8 | Medium | 2025-12-17 |
| CVE-2025-62786 | Wazuh 安全漏洞 — wazuh | 9.8AI | CriticalAI | 2025-10-29 |
| CVE-2025-61690 | KEYENCE KV STUDIO 安全漏洞 — KV STUDIO | 7.8 | High | 2025-10-02 |
| CVE-2025-53101 | ImageMagick 安全漏洞 — ImageMagick | 7.4 | High | 2025-07-14 |
| CVE-2025-20695 | MediaTek Chipsets 安全漏洞 — MT6639, MT6653, MT6985, MT6989, MT6990, MT6991, MT7925, MT7927, MT8196, MT8678, MT8796 | 6.5AI | MediumAI | 2025-07-08 |
| CVE-2025-20694 | MediaTek Chipsets 安全漏洞 — MT2718, MT6639, MT6653, MT6985, MT6989, MT6990, MT6991, MT7925, MT7927, MT8113, MT8115, MT8127, MT8163, MT8168, MT8169, MT8173, MT8183, MT8186, MT8188, MT8195, MT8196, MT8370, MT8390, MT8391, MT8395, MT8512, MT8516, MT8519, MT8676, MT8678, MT8695, MT8696, MT8698, MT8786, MT8792, MT8796, MT8893 | 6.5 | - | 2025-07-08 |
| CVE-2025-4373 | glib 安全漏洞 | 4.8 | Medium | 2025-05-06 |
| CVE-2023-25610 | Fortinet FortiOS和FortiProxy 安全漏洞 — FortiSwitchManager | 9.3 | Critical | 2025-03-24 |
| CVE-2025-27440 | Zoom Workplace 安全漏洞 — Zoom Workplace Apps | 8.5 | High | 2025-03-11 |
| CVE-2025-27439 | Zoom Workplace 安全漏洞 — Zoom Workplace Apps | 8.5 | High | 2025-03-11 |
| CVE-2020-9086 | Huawei 4G Router B612安全漏洞 — HUAWEI 4G Router B612 | 4.3 | Medium | 2024-12-27 |
| CVE-2024-52990 | Adobe Animate 安全漏洞 — Animate | 7.8 | High | 2024-12-10 |
| CVE-2023-48230 | capnproto 安全漏洞 — capnproto | 5.9 | Medium | 2023-11-21 |
| CVE-2023-32614 | Accusoft ImageGear 缓冲区错误漏洞 — ImageGear | 7.0 | High | 2023-09-25 |
| CVE-2023-31130 | c-ares 缓冲区错误漏洞 — c-ares | 4.1 | Medium | 2023-05-25 |
| CVE-2022-33896 | Hancom Office 安全漏洞 — Hancom Office 2020 | 7.8 | - | 2022-10-07 |
| CVE-2022-20683 | Cisco IOS XE Software缓冲区错误漏洞 — Cisco IOS XE Software | 8.6 | High | 2022-04-15 |
| CVE-2021-38578 | Tianocore Edk2 缓冲区错误漏洞 — EDK II | 7.4 | High | 2022-03-03 |
| CVE-2021-38575 | Tianocore Edk2 缓冲区错误漏洞 — EDK II | 8.1 | - | 2021-12-01 |
| CVE-2021-36064 | Adobe XMP Toolkit SDK 安全漏洞 — XMP Toolkit | 7.8 | High | 2021-09-01 |
| CVE-2018-15361 | UltraVNC 缓冲区错误漏洞 — UltraVNC | 9.8 | - | 2019-03-05 |
| CVE-2018-5388 | strongSwan 缓冲区错误漏洞 — strongSwan | 6.5 | - | 2018-05-31 |
CWE-124(缓冲区下溢) 是常见的弱点类别,本平台收录该类弱点关联的 29 条 CVE 漏洞。