CWE-682 数值计算不正确 类弱点 42 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-682属于逻辑计算错误漏洞,指软件在执行关键计算时产生非预期结果。攻击者常利用此缺陷操纵资源分配或权限判定,从而绕过安全控制或引发拒绝服务。开发者应避免使用浮点数进行精确比较,严格验证输入范围,并在涉及安全决策的计算环节引入冗余校验机制,确保逻辑严密性与数值准确性。
img_t table_ptr; /*struct containing img data, 10kB each*/ int num_imgs; ... num_imgs = get_num_imgs(); table_ptr = (img_t*)malloc(sizeof(img_t)*num_imgs); ...... int touchdowns = team.getTouchdowns(); int yardsGained = team.getTotalYardage(); System.out.println(team.getName() + " averages " + yardsGained / touchdowns + "yards gained for every touchdown scored"); ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-44498 | 斑马计价器Coinbase和P2SH签名操作计数偏低 — zebra | - | - | 2026-05-08 |
| CVE-2026-1229 | CIRCL 安全漏洞 — CIRCL | 7.5AI | HighAI | 2026-02-24 |
| CVE-2026-24783 | soroban-fixed-point-math 安全漏洞 — soroban-fixed-point-math | 7.5 | High | 2026-01-27 |
| CVE-2026-21911 | Juniper Junos OS Evolved 安全漏洞 — Junos OS Evolved | 6.5 | Medium | 2026-01-15 |
| CVE-2025-59047 | Matrix Rust SDK 安全漏洞 — matrix-rust-sdk | 7.5AI | HighAI | 2025-09-11 |
| CVE-2025-54427 | Polkadot Frontier 代码问题漏洞 — frontier | - | -AI | 2025-07-28 |
| CVE-2025-5372 | libssh 安全漏洞 — libssh | 5.0 | Medium | 2025-07-04 |
| CVE-2025-0036 | AMD Versal Adaptive SoC 安全漏洞 — Versal Adaptive SoC Devices | 3.2 | Low | 2025-06-09 |
| CVE-2025-26622 | Vyper 安全漏洞 — vyper | - | - | 2025-02-21 |
| CVE-2024-11407 | gRPC 安全漏洞 — gRPC-C++ | 7.5AI | HighAI | 2024-11-26 |
| CVE-2024-45056 | ZKsync Era 安全漏洞 — era-compiler-solidity | 5.9 | Medium | 2024-08-29 |
| CVE-2024-6287 | Linaro Trusted Firmware-A 安全漏洞 — rcar_gen3_v2.5 | 7.5 | High | 2024-06-24 |
| CVE-2024-32873 | Evmos 安全漏洞 — evmos | 3.5 | Low | 2024-06-06 |
| CVE-2024-34704 | ZKsync Era 安全漏洞 — era-compiler-solidity | 5.9 | Medium | 2024-05-13 |
| CVE-2023-35642 | Microsoft Windows Internet Connection Sharing (ICS) 安全漏洞 — Windows 10 Version 1809 | 6.5 | Medium | 2023-12-12 |
| CVE-2023-35641 | Microsoft Windows Internet Connection Sharing (ICS) 安全漏洞 — Windows 10 Version 1809 | 8.8 | High | 2023-12-12 |
| CVE-2023-42460 | Vyper 安全漏洞 — vyper | 5.3 | Medium | 2023-09-26 |
| CVE-2023-2163 | Linux kernel 安全漏洞 — Linux Kernel | 10.0 | Critical | 2023-09-20 |
| CVE-2023-2423 | Rockwell Automation Armor PowerFlex 安全漏洞 — Armor PowerFlex | 8.6 | High | 2023-08-08 |
| CVE-2023-28431 | Frontier 安全漏洞 — frontier | 7.5 | High | 2023-03-22 |
| CVE-2023-1296 | HashiCorp Nomad 安全漏洞 — Nomad | 2.7 | Low | 2023-03-14 |
| CVE-2023-26488 | OpenZeppelin 安全漏洞 — openzeppelin-contracts | 6.5 | Medium | 2023-03-03 |
| CVE-2022-36795 | F5 BIG-IP 安全漏洞 — BIG-IP | 5.3 | Medium | 2022-10-19 |
| CVE-2022-39242 | Frontier 安全漏洞 — frontier | 5.3 | Medium | 2022-09-24 |
| CVE-2022-31198 | OpenZeppelin 安全漏洞 — openzeppelin-contracts | 7.5 | High | 2022-08-01 |
| CVE-2022-23001 | Western Digital Sweet B 安全漏洞 — Sweet B Library | 5.3 | Medium | 2022-07-29 |
| CVE-2022-31169 | Wasmtime 安全漏洞 — wasmtime | 5.9 | Medium | 2022-07-21 |
| CVE-2022-31104 | Wasmtime 安全漏洞 — wasmtime | 4.8 | Medium | 2022-06-27 |
| CVE-2022-30600 | Moodle 安全漏洞 — moodle | 8.2 | - | 2022-05-18 |
| CVE-2022-23066 | Solana Rbpf 安全漏洞 — rbpf | 9.1 | Critical | 2022-05-09 |
CWE-682(数值计算不正确) 是常见的弱点类别,本平台收录该类弱点关联的 42 条 CVE 漏洞。