Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-265 (权限/沙箱问题) — Vulnerability Class 12

12 vulnerabilities classified as CWE-265 (权限/沙箱问题). AI Chinese analysis included.

This page documents the vulnerability aggregation details for Weakness type CWE-265, specifically focusing on issues where improper handling of object instantiation or reference management leads to security flaws. It aggregates data on multiple vulnerability categories including object injection, reference manipulation, and improper validation of user-supplied inputs that affect application logic and data integrity. The content covers incidents reported from January 2018 through December 2023, providing a comprehensive historical view of how this specific weakness class has manifested in real-world software environments. Users can track vendor advisories related to this weakness to monitor remediation efforts across different platforms and organizations. The page helps in understanding the broader context of CWE-265 by analyzing common patterns, affected architectures, and typical exploitation scenarios. Readers can look up a product's vulnerability history to identify recurring issues within specific software families or development frameworks. This resource serves as a reference for security researchers and developers seeking to identify and mitigate risks associated with improper object handling and reference management errors. By examining aggregated reports, stakeholders can better assess the prevalence of this weakness in their technology stack and prioritize secure coding practices that prevent instantiation vulnerabilities. The information supports risk management decisions by highlighting trends in how CWE-265 impacts system stability and confidentiality over time.

Vulnerabilities classified as CWE-265 (权限/沙箱问题) represent 12 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.