#cwe-371

共收录 3 条相关安全情报。

← 返回所有主题
CVE-2026-82551

A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
推荐 8.4
Conf: 50%

A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

💡 风险点: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: 有可用补丁/修复方案 (+3) | Primary 数据源 (+3) | 包含 CVE (+2) | LLM 评分加成 (+0.4)
CVE-2026-14685

该漏洞存在于 HdrHistogram 库(版本 up to 2.2.2)的 AbstractHistogram.java 文件中的 recordValueWithCount 函数。由于对参数 Count 的操作存在状态问题,攻击者通过本地访问并执行低权限操作,可能导致应用程序的完整性受损。该漏洞已被公开披露,但厂商尚未回应。CVSS 评分为 3.3(低危),攻击向量为本地(AV:L),攻击复杂度低(AC:L),需要低权限(PR:L),无需用户交互(UI:N),影响范围未改变(S:U),对机密性无影响,对完整性有低影响,对可用性无影响。建议用户升级到已修复版本(如存在)或限制本地访问权限。

💡 影响/原因: 该漏洞虽然 CVSS 评分低,但已被公开披露且厂商未修复,可能被本地攻击者利用以破坏数据完整性。HdrHistogram 是广泛使用的性能监控库,受影响版本需要关注。

排序因子: 有可用补丁/修复方案 (+3) | Primary 数据源 (+3) | LLM 评分加成 (+0.4)