CWE-1260 类弱点 11 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-1260 属于内存保护绕过漏洞。当产品允许受保护内存区域重叠时,硬件隔离与访问控制策略可能被破坏。攻击者通常利用此缺陷,通过构造重叠的地址空间来规避读写限制,从而访问或修改本应受保护的敏感数据。开发者应避免动态重映射内存时产生区域冲突,确保内存边界清晰且互不重叠,以维持系统的安全隔离机制。
Non_privileged_SW can program the Address_range register for Region_2 so that its address overlaps with the ranges defined by Region_0 or Region_1. Using this capability, it is possible for Non_privileged_SW to block any memory region from being accessed by Privileged_SW, i.e., Region_0 and Region_1.Ensure that software accesses to memory regions are only permitted if all three filters permit access. Additionally, the scheme could define a memory region priority to ensure that Region_2 (the memory region defined by Non_privileged_SW) cannot overlap Region_0 or Region_1 (which are used by Privileged_SW).... localparam logic[63:0] PLICLength = 64'h03FF_FFFF; localparam logic[63:0] UARTLength = 64'h0011_1000; localparam logic[63:0] AESLength = 64'h0000_1000; localparam logic[63:0] SPILength = 64'h0080_0000; ... typedef enum logic [63:0] { ... PLICBase = 64'h0C00_0000, UARTBase = 64'h1000_0000, AESBase = 64'h1010_0000, SPIBase = 64'h2000_0000, ...... localparam logic[63:0] PLICLength = 64'h03FF_FFFF; localparam logic[63:0] UARTLength = 64'h0000_1000; localparam logic[63:0] AESLength = 64'h0000_1000; localparam logic[63:0] SPILength = 64'h0080_0000; ... typedef enum logic [63:0] { ... PLICBase = 64'h0C00_0000, UARTBase = 64'h1000_0000, AESBase = 64'h1010_0000, SPIBase = 64'h2000_0000, ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2018-25240 | Watchr 安全漏洞 — Watchr | 6.2 | Medium | 2026-04-04 |
| CVE-2018-25238 | VSCO 安全漏洞 — VSCO | 6.2 | Medium | 2026-04-04 |
| CVE-2019-25602 | GSearch 安全漏洞 — GSearch | 5.5 | Medium | 2026-03-22 |
| CVE-2019-25592 | XLineSoft PHPRunner 安全漏洞 — PHPRunner | 6.2 | Medium | 2026-03-22 |
| CVE-2019-25585 | Deluge 安全漏洞 — Deluge | 6.2 | Medium | 2026-03-22 |
| CVE-2019-25572 | NordVPN 安全漏洞 — NordVPN | 6.2 | Medium | 2026-03-21 |
| CVE-2019-25570 | RealTerm Serial Terminal 安全漏洞 — RealTerm: Serial Terminal | 5.5 | Medium | 2026-03-21 |
| CVE-2019-25559 | Nsasoft SpotPaltalk 安全漏洞 — SpotPaltalk | 5.5 | Medium | 2026-03-21 |
| CVE-2025-0012 | AMD EPYC 安全漏洞 — AMD EPYC™ 9005 Series Processors | 8.1AI | HighAI | 2026-02-10 |
| CVE-2025-29948 | AMD EPYC Processor 安全漏洞 — AMD EPYC™ 9005 Series Processors | 7.1AI | HighAI | 2026-02-10 |
| CVE-2022-27813 | Motorola MTM5000 安全漏洞 — Mobile Radio | 8.1 | High | 2023-10-19 |
CWE-1260 是常见的弱点类别,本平台收录该类弱点关联的 11 条 CVE 漏洞。