VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,399)

page 105 of 170
  • CVE-2023-38650HigJan 8, 2024
    risk 0.46cvss 7.0epss 0.00

    Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode times parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. A victim would need to open a malicious file to trigger these vulnerabilities.This…

  • CVE-2023-35992HigJan 8, 2024
    risk 0.46cvss 7.0epss 0.00

    An integer overflow vulnerability exists in the FST fstReaderIterBlocks2 vesc allocation functionality of GTKWave 3.3.115, when compiled as a 32-bit binary. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this…

  • CVE-2023-35128HigJan 8, 2024
    risk 0.46cvss 7.0epss 0.00

    An integer overflow vulnerability exists in the fstReaderIterBlocks2 time_table tsec_nitems functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-32650HigJan 8, 2024
    risk 0.46cvss 7.0epss 0.00

    An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle functionality of GTKWave 3.3.115, when compiled as a 32-bit binary. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this…

  • CVE-2023-25516HigJul 4, 2023
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause an integer overflow, which may lead to information disclosure and denial of service.

  • CVE-2023-29364HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Authentication Elevation of Privilege Vulnerability

  • CVE-2023-23385HigMar 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability

  • CVE-2022-47092HigJan 5, 2023
    risk 0.46cvss 7.1epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is contains an Integer overflow vulnerability in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8316

  • CVE-2022-42263HigDec 30, 2022
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an Integer overflow may lead to denial of service or information disclosure.

  • CVE-2022-35951HigSep 23, 2022
    risk 0.46cvss 7.0epss 0.03

    Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may cause an integer overflow, a…

  • CVE-2021-22437HigFeb 25, 2022
    risk 0.46cvss 7.0epss 0.00

    There is a software integer overflow leading to a TOCTOU condition in smartphones. Successful exploitation of this vulnerability may cause random address access.

  • CVE-2021-25803HigJul 26, 2021
    risk 0.46cvss 7.1epss 0.01

    A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

  • CVE-2018-10195HigJun 2, 2021
    risk 0.46cvss 7.1epss 0.00

    lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.

  • CVE-2021-23840HigFeb 16, 2021
    risk 0.46cvss 7.5epss 0.51

    Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will…

  • CVE-2019-10623HigApr 16, 2020
    risk 0.46cvss 7.1epss 0.00

    Possible integer overflow can happen in host driver while processing user controlled string due to improper validation on data received. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2019-17498HigOct 21, 2019
    risk 0.46cvss 8.1epss 0.04

    In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive…

  • CVE-2019-10142HigJul 30, 2019
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed to an ioctl was incorrectly validated and used in size calculations for the page size calculation. An attacker can use this flaw…

  • CVE-2018-20506HigApr 3, 2019
    risk 0.46cvss 8.1epss 0.08

    SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by…

  • CVE-2018-20346HigDec 21, 2018
    risk 0.46cvss 8.1epss 0.10

    SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run…

  • CVE-2016-6328HigOct 31, 2018
    risk 0.46cvss 8.1epss 0.02

    A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).