CWE-197 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-197 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2022-42475A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 t…99.5%심각9.8CVE-2026-78512Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code ov…0.8%높음8.8CVE-2026-69512Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privile…0.8%높음8.0CVE-2026-76151Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNet…0.6%보통4.6CVE-2026-96280The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functio…0.6%높음7.5CVE-2026-19667If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 b…0.5%높음7.5CVE-2026-87529Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker …0.5%심각9.6CVE-2026-68880Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges ove…0.4%높음8.0
전체 목록
15건
CVE-2026-63449Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.4%낮음3.7
CVE-2026-69822Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.0.3%높음7.8
CVE-2026-68895Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose informatio…0.3%보통5.5
CVE-2026-69535Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.0.2%높음7.8
CVE-2026-101085Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administr…0.2%높음7.1
CVE-2026-69578Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally.0.2%높음7.0
CVE-2026-86315An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an att…0.1%보통6.2
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.