CWE-1325 类弱点 12 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-1325 属于资源管理不当漏洞,指程序为每个对象单独分配内存,却未限制所有对象消耗的总内存量。攻击者可通过触发大量对象创建,耗尽系统内存导致拒绝服务。开发者应避免仅限制单次分配大小,而需实施全局内存配额监控,确保累积分配量不超过安全阈值,从而防止资源枯竭。
// Gets the size from the number of objects in a database, which over time can conceivably get very large int end_limit = get_nmbr_obj_from_db(); int i; int *base = NULL; int *p =base; for (i = 0; i < end_limit; i++) { *p = alloca(sizeof(int *)); // Allocate memory on the stack p = *p; // // Point to the next location to be saved }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-6535 | Wireshark 顺序内存分配控制不当漏洞 — Wireshark | 5.5 | Medium | 2026-04-30 |
| CVE-2026-6533 | Wireshark 不正确的顺序内存分配漏洞 — Wireshark | 5.5 | Medium | 2026-04-30 |
| CVE-2026-6869 | Wireshark 内存分配不当漏洞 — Wireshark | 5.5 | Medium | 2026-04-30 |
| CVE-2026-6867 | Wireshark 顺序内存分配控制不当漏洞 — Wireshark | 5.5 | Medium | 2026-04-30 |
| CVE-2026-3201 | Wireshark 安全漏洞 — Wireshark | 4.7 | Medium | 2026-02-25 |
| CVE-2026-24819 | weixin4j 安全漏洞 — weixin4j | 9.1AI | CriticalAI | 2026-01-27 |
| CVE-2025-13945 | Wireshark 安全漏洞 — Wireshark | 5.5 | Medium | 2025-12-03 |
| CVE-2025-2240 | Smallrye 安全漏洞 | 7.5 | High | 2025-03-12 |
| CVE-2023-52891 | Siemens 多款产品安全漏洞 — SIMATIC Energy Manager Basic | 5.3 | Medium | 2024-07-09 |
| CVE-2024-2511 | OpenSSL 安全漏洞 — OpenSSL | 7.5AI | HighAI | 2024-04-08 |
| CVE-2023-28968 | Juniper Networks Junos OS 安全漏洞 — Junos OS | 5.3 | Medium | 2023-04-17 |
| CVE-2021-43174 | NLnet Labs Routinator 缓冲区错误漏洞 — Routinator | 7.5 | - | 2021-11-09 |
CWE-1325 是常见的弱点类别,本平台收录该类弱点关联的 12 条 CVE 漏洞。