彙總 boost 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
已披露問題常與 輸入驗證問題、緩衝區溢位、拒絕服務與整數處理缺陷 相關,可能在 軟體部署與生產負載 場景中帶來 異常行為 等暴露風險。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2016-9840 | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | [email protected] | 8.8 | 9.83% | 2017-05-23 | 2026-05-13 |
| CVE-2013-0252 | boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which might allow remote attackers to bypass input validation protection mechanisms via crafted trailing bytes. | [email protected] | 5.0 | 0.92% | 2013-03-12 | 2026-04-29 |
| CVE-2012-2677 | Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected. | [email protected] | 5.0 | 0.82% | 2012-07-25 | 2026-04-29 |
| CVE-2008-0172 | The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression. | [email protected] | 5.0 | 2.19% | 2008-01-17 | 2026-04-23 |
| CVE-2008-0171 | regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression. | [email protected] | 5.0 | 3.41% | 2008-01-17 | 2026-04-23 |