CWE-839 6 個 CVE MITRE 定義 ↗

CWE-839:Numeric Range Comparison Without Minimum Check

概覽

CWE-839(Numeric Range Comparison Without Minimum Check)描述一種在漏洞資料庫與安全評估中使用的弱點類型;定義、背景與對應 CVE 見下方各節。

安全影響
安全影響:因產品與情境而異;請結合 CVE 紀錄、嚴重度評分與 MITRE 說明進行優先級判斷。

描述

The product checks a value to ensure that it is less than or equal to a maximum, but it does not also verify that the value is greater than or equal to the minimum.

適用平台

類型 名稱 普遍性 OS / CPE
language C Often
language C++ Often

本庫相關 CVE

下列 CVE 在本庫中對應到該弱點,並保留以便追溯與檢索。

CVE 公開時間 摘要
CVE-2026-53176 2026-06-25 In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() comp…
CVE-2026-56968 2026-06-23 GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
CVE-2026-48840 2026-05-29 Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
CVE-2023-0425 2023-08-07 ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who succ…
CVE-2023-22854 2023-02-13 The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL param…
CVE-2019-20925 2020-11-24 An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects Mon…

內容提交

名稱
CWE Content Team
組織
MITRE
日期
2011-03-24
版本
1.12

內容修訂

日期 名稱 版本 重要性 評論
2011-06-01 CWE Content Team 1.13 updated Common_Consequences
2012-05-11 CWE Content Team 2.2 updated Demonstrative_Examples, References, Relationships
2014-02-18 CWE Content Team 2.6 updated Relationships
2018-03-27 CWE Content Team 3.1 updated Description
2019-01-03 CWE Content Team 3.2 updated Relationships
2023-01-31 CWE Content Team 4.10 updated Alternate_Terms, Description
2023-04-27 CWE Content Team 4.11 updated Relationships
2023-06-29 CWE Content Team 4.12 updated Mapping_Notes
2023-10-26 CWE Content Team 4.13 updated Observed_Examples
2025-09-09 CWE Content Team 4.18 updated Demonstrative_Examples
2025-12-11 CWE Content Team 4.19 updated Detection_Factors, Time_of_Introduction, Weakness_Ordinalities
cvelogic Threat Intelligence