VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,399)

page 110 of 170
  • CVE-2023-42563MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.

  • CVE-2023-42562MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.

  • CVE-2023-21371MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    In Secure Element, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21370MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    In the Security Element API, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-32829MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07713478; Issue ID: ALPS07713478.

  • CVE-2023-32828MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767817; Issue ID: ALPS07767817.

  • CVE-2023-32823MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In rpmb , there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07912966; Issue ID: ALPS07912966.

  • CVE-2023-21655MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Audio while validating and mapping metadata.

  • CVE-2023-21644MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.

  • CVE-2023-20756MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ID: ALPS07549928.

  • CVE-2023-20755MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07510064; Issue ID: ALPS07509605.

  • CVE-2023-20682MedApr 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In wlan, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441605; Issue ID: ALPS07441605.

  • CVE-2023-20663MedApr 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In wlan, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560741; Issue ID: ALPS07560741.

  • CVE-2023-20662MedApr 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In wlan, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560765; Issue ID: ALPS07560765.

  • CVE-2023-20661MedApr 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In wlan, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560782; Issue ID: ALPS07560782.

  • CVE-2023-28613MedApr 4, 2023
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, and Exynos Modem 5300. An integer overflow in IPv4 fragment handling can occur due to insufficient parameter validation when reassembling these fragments.

  • CVE-2023-21065MedMar 24, 2023
    risk 0.44cvss 6.7epss 0.00

    In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid…

  • CVE-2023-20602MedFeb 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494107; Issue ID: ALPS07494107.

  • CVE-2022-20454MedNov 8, 2022
    risk 0.44cvss 6.7epss 0.00

    In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11…

  • CVE-2022-26466MedSep 6, 2022
    risk 0.44cvss 6.7epss 0.00

    In audio ipi, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06558777; Issue ID: ALPS06558777.