CWE-129 对数组索引的验证不恰当 类弱点 182 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-129 属于数组索引验证不当漏洞,指程序使用不可信输入计算数组索引时,未进行有效校验或校验逻辑错误,导致索引越界。攻击者通常通过构造恶意输入,使索引指向非法内存位置,从而引发缓冲区溢出、数据篡改或拒绝服务攻击。开发者应严格验证输入数据的范围,确保其始终处于数组合法边界内,并采用安全的边界检查机制,从源头阻断越界访问风险。
public String getValue(int index) { return array[index]; }private void buildList ( int untrustedListSize ){ if ( 0 > untrustedListSize ){ die("Negative value supplied for list size, die evil hacker!"); } Widget[] list = new Widget [ untrustedListSize ]; list[0] = new Widget(); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-49832 | Qualcomm Chipsets 输入验证错误漏洞 — Snapdragon | 7.8 | High | 2025-02-03 |
| CVE-2024-45582 | Qualcomm Chipsets 输入验证错误漏洞 — Snapdragon | 7.8 | High | 2025-02-03 |
| CVE-2024-45569 | Qualcomm Chipsets 输入验证错误漏洞 — Snapdragon | 9.8 | Critical | 2025-02-03 |
| CVE-2024-45550 | Qualcomm Chipsets 输入验证错误漏洞 — Snapdragon | 7.8 | High | 2025-01-06 |
| CVE-2024-33044 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.4 | High | 2024-12-02 |
| CVE-2024-47249 | Apache NimBLE 安全漏洞 — Apache NimBLE | 6.5AI | MediumAI | 2024-11-26 |
| CVE-2024-51517 | Huawei HarmonyOS 安全漏洞 — HarmonyOS | 5.1 | Medium | 2024-11-05 |
| CVE-2024-33032 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 6.7 | Medium | 2024-11-04 |
| CVE-2024-5680 | Schneider Electric EcoStruxure Foxboro DCS 输入验证错误漏洞 — EcoStruxure Foxboro DCS Core Control Services | 7.1 | High | 2024-07-11 |
| CVE-2024-21522 | Audify.js 安全漏洞 — audify | 7.5 | High | 2024-07-10 |
| CVE-2024-32673 | SAMSUNG WALRUS 安全漏洞 — Walrus | 5.5 | Medium | 2024-07-03 |
| CVE-2024-22181 | libigl 安全漏洞 — libigl | 7.8 | High | 2024-05-28 |
| CVE-2023-40477 | RAR 安全漏洞 — WinRAR | 7.8 | - | 2024-05-03 |
| CVE-2023-27349 | SUSE Linux Enterprise Server 安全漏洞 — BlueZ | 8.0 | - | 2024-05-03 |
| CVE-2023-51455 | DJI Mavic和Matrice安全漏洞 — Mavic 3 Pro | 6.8 | Medium | 2024-04-02 |
| CVE-2023-33111 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 5.5 | Medium | 2024-04-01 |
| CVE-2024-29231 | Synology Surveillance Station 安全漏洞 — Surveillance Station | 5.4 | Medium | 2024-03-28 |
| CVE-2024-2214 | Eclipse ThreadX RTOS 安全漏洞 — ThreadX | 7.0 | High | 2024-03-26 |
| CVE-2024-0901 | wolfSSL 安全漏洞 — wolfSSL | 7.5 | High | 2024-03-25 |
| CVE-2024-21493 | caddy-security 安全漏洞 — github.com/greenpau/caddy-security | 5.3 | Medium | 2024-02-17 |
| CVE-2024-24563 | Vyper 输入验证错误漏洞 — vyper | 9.8 | Critical | 2024-02-07 |
| CVE-2023-43535 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.4 | High | 2024-02-06 |
| CVE-2023-35994 | GTKWave 输入验证错误漏洞 — GTKWave | 7.8 | High | 2024-01-08 |
| CVE-2023-35995 | GTKWave 输入验证错误漏洞 — GTKWave | 7.8 | High | 2024-01-08 |
| CVE-2023-35997 | GTKWave 输入验证错误漏洞 — GTKWave | 7.8 | High | 2024-01-08 |
| CVE-2023-35996 | GTKWave 输入验证错误漏洞 — GTKWave | 7.8 | High | 2024-01-08 |
| CVE-2023-39234 | GTKWave 输入验证错误漏洞 — GTKWave | 7.8 | High | 2024-01-08 |
| CVE-2023-39235 | GTKWave 输入验证错误漏洞 — GTKWave | 7.8 | High | 2024-01-08 |
| CVE-2023-33053 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.4 | High | 2023-12-05 |
| CVE-2023-6298 | iText 输入验证错误漏洞 — iText | 4.3 | Medium | 2023-11-26 |
CWE-129(对数组索引的验证不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 182 条 CVE 漏洞。