汇总 boost 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。
已披露问题常与 输入验证问题、缓冲区溢出、拒绝服务与整数处理缺陷 相关,可能在 软件部署与生产负载 场景中带来 异常行为 等暴露风险。
相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2016-9840 | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | [email protected] | 8.8 | 9.83% | 2017-05-23 | 2026-05-13 |
| CVE-2013-0252 | boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which might allow remote attackers to bypass input validation protection mechanisms via crafted trailing bytes. | [email protected] | 5.0 | 0.92% | 2013-03-12 | 2026-04-29 |
| CVE-2012-2677 | Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected. | [email protected] | 5.0 | 0.82% | 2012-07-25 | 2026-04-29 |
| CVE-2008-0172 | The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression. | [email protected] | 5.0 | 2.19% | 2008-01-17 | 2026-04-23 |
| CVE-2008-0171 | regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression. | [email protected] | 5.0 | 3.41% | 2008-01-17 | 2026-04-23 |