CWE-754 对因果或异常条件的不恰当检查 类弱点 272 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-754 属于异常条件检查不当漏洞,指软件未正确验证低频但关键的异常状态,如内存不足或权限受限。攻击者常通过耗尽资源或模拟恶意客户端触发这些未处理条件,导致服务拒绝或逻辑错误。开发者应完善错误处理机制,对所有预期外的系统状态进行严格校验与防御性编程,确保在极端情况下仍能安全降级或报错,避免程序崩溃或被利用。
char buf[10], cp_buf[10]; fgets(buf, 10, stdin); strcpy(cp_buf, buf);buf = (char*) malloc(req_size); strncpy(buf, xfer, req_size);| CVE ID | タイトル | CVSS | 深刻度 | 公開日 |
|---|---|---|---|---|
| CVE-2021-0236 | Junos OS: A specific BGP VPNv6 flowspec message causes routing protocol daemon (rpd) process to crash with a core. — Junos OS | 6.5 | Medium | 2021-04-22 |
| CVE-2021-0228 | Junos OS: MX Series: DDoS LACP violation upon receipt of specific layer 2 frames in EVPN-VXLAN deployment — Junos OS | 6.5 | Medium | 2021-04-22 |
| CVE-2021-0225 | Junos OS Evolved: Stateless IP firewall filter does not work as expected — Junos OS Evolved | 5.8 | Medium | 2021-04-22 |
| CVE-2021-1446 | Cisco IOS XE Software DNS NAT Protocol Application Layer Gateway Denial of Service Vulnerability — Cisco IOS XE Software | 8.6 | High | 2021-03-24 |
| CVE-2020-27274 | Honeywell OPC UA Tunneller 代码问题漏洞 — OPC UA Tunneller | 7.5 | - | 2021-01-26 |
| CVE-2020-24677 | Insecure Web Service in Symphony Plus — ABB Ability™ Symphony® Plus Operations | 8.8 | High | 2020-12-22 |
| CVE-2020-7549 | Schneider Electric Modicon M340 代码问题漏洞 — Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions) | 5.3 | - | 2020-12-11 |
| CVE-2020-7543 | 多款Schneider Electric产品代码问题漏洞 — Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7542 | 多款Schneider Electric产品代码问题漏洞 — Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7539 | 多款 Schneider Electric 产品代码问题漏洞 — Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7537 | 多款Schneider Electric产品代码问题漏洞 — Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7536 | Schneider Electric Modicon M340 代码问题漏洞 — Modicon M340 CPUs (BMXP34* versions prior to V3.30) and Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3.4, BMXNOE0110 (H) versions prior to V6.6, and BMXNOR0200H all versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7538 | Schneider Electric EcoStruxure Control Expert 代码问题漏洞 — PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) | 7.5 | - | 2020-11-19 |
| CVE-2020-1999 | PAN-OS: Threat signatures are evaded by specifically crafted packets — PAN-OS | 5.3 | Medium | 2020-11-12 |
| CVE-2020-16125 | gdm3 would start gnome-initial-setup if it cannot contact accountservice — GDM3 | 7.2 | High | 2020-11-10 |
| CVE-2020-3421 | Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities — Cisco IOS XE Software | 8.6 | High | 2020-09-24 |
| CVE-2020-3480 | Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities — Cisco IOS XE Software | 8.6 | High | 2020-09-24 |
| CVE-2020-5420 | Gorouter is vulnerable to DoS attack via invalid HTTP responses — Routing | 7.7 | - | 2020-09-03 |
| CVE-2020-3449 | Cisco IOS XR Software Additional Paths Denial of Service Vulnerability — Cisco IOS XR Software | 4.3 | Medium | 2020-08-17 |
| CVE-2020-7477 | 多款Schneider Electric产品代码问题漏洞 — Modicon Quantum Ethernet Network module and Quantum / Premium COPRO (Quantum Ethernet Network module 140NOE771x1, versions 7.0 and prior, Quantum processors with integrated Ethernet – 140CPU65xxxxx, all versions, Premium processors with integrated Ethernet, all versions) | 7.5 | - | 2020-03-23 |
| CVE-2020-5215 | Segmentation faultin TensorFlow when converting a Python string to tf.float16 — TensorFlow | 5.0 | Medium | 2020-01-28 |
| CVE-2019-15989 | Cisco IOS XR Software Border Gateway Protocol Attribute Denial of Service Vulnerability — Cisco IOS XR Software | 6.8 | - | 2020-01-26 |
| CVE-2018-7794 | 多款Schneider Electric产品代码问题漏洞 — Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) | 7.5 | - | 2020-01-06 |
| CVE-2019-6857 | 多款Schneider Electric产品代码问题漏洞 — Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) | 7.5 | - | 2020-01-06 |
| CVE-2019-6856 | 多款Schneider Electric产品代码问题漏洞 — Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) | 7.5 | - | 2020-01-06 |
| CVE-2019-11779 | Eclipse Mosquitto 代码问题漏洞 — Eclipse Mosquitto | 8.1 | - | 2019-09-19 |
| CVE-2019-6813 | Schneider Electric Modicon M340和BMXNOR0200H Ethernet/Serial RTU module 代码问题漏洞 — BMXNOR0200H Ethernet / Serial RTU module | 7.5 | - | 2019-09-17 |
| CVE-2019-6811 | Schneider Electric Quantum 140 NOE771x1 代码问题漏洞 — Modicon Quantum 140 NOE771x1 | 7.5 | - | 2019-09-17 |
| CVE-2019-6833 | 多款Schneider Electric产品代码问题漏洞 — Magelis HMI Panels | 7.5 | - | 2019-09-17 |
| CVE-2019-6831 | Schneider Electric BMXNOR0200H Ethernet/Serial RTU module 代码问题漏洞 — BMXNOR0200H Ethernet / Serial RTU module | 7.5 | - | 2019-09-17 |
CWE-754(对因果或异常条件的不恰当检查) 是常见的弱点类别,本平台收录该类弱点关联的 272 条 CVE 漏洞。